CVE-2026-69859
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate
CVSS
7.0
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-191 · CWE-367
Not enough EPSS history yet.
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-784647.0 HIG—
———Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.6hCVE-2026-784536.5 MED—
———Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.6hCVE-2026-774885.5 MED—
———Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.6hCVE-2026-729476.4 MED—
———Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.6hCVE-2026-713528.8 HIG—
———Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.6hCVE-2026-698249.8 CRI—
———Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.6h