CVE-2026-77097
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Softwar
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-306
Not enough EPSS history yet.
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-839915.5 MED—
———Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.3hCVE-2026-730045.5 MED—
———Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.3hCVE-2026-729645.5 MED—
———Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.3hCVE-2026-696745.5 MED—
———Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally.3hCVE-2026-695545.5 MED—
———Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.3hCVE-2026-695287.8 HIG—
———Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.3h