CVE-2026-69844
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS
7.8
High
EPSS
0.3%
p25
KEV
—
Exploit Today
7
0-100
Published: Sep 8, 2026 · Last modified: Sep 9, 2026 · CWE-125
0.3%EPSS · 30 days0.3%
2026-09-092026-09-11
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-905608.2 HIG—
———zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.10hCVE-2026-905576.1 MED—
———Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.10hCVE-2026-78546——
——0Out-of-bounds read vulnerability in Citirx Workspace app for Windows.
This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.1dCVE-2026-13326—4.7%
——1An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.2dCVE-2026-891603.7 LOW12.6%
——4PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.2dCVE-2026-891562.9 LOW1.0%
——0PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.2d