CVE-2026-69295
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CVSS
7.8
High
EPSS
0.3%
p25
KEV
—
Exploit Today
7
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-20 · CWE-125
0.3%EPSS · 30 days0.3%
2026-09-092026-09-11
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-905608.2 HIG—
———zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.10hCVE-2026-905576.1 MED—
———Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.10hCVE-2026-78546——
——0Out-of-bounds read vulnerability in Citirx Workspace app for Windows.
This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.1dCVE-2026-85979——
——0Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system.2dCVE-2026-13326—4.7%
——1An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.2dCVE-2026-891603.7 LOW12.6%
——4PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.2d