CVE-2026-69321
published 2026-09-08CVE-2026-69321: Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.
PriorityP431medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.30%
21.0th percentile
Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.9512 | 10.0.14393.9512 |
| microsoft | windows_10_1809 | < 10.0.17763.9245 | 10.0.17763.9245 |
| microsoft | windows_10_21h2 | < 10.0.19044.7725 | 10.0.19044.7725 |
| microsoft | windows_10_22h2 | < 10.0.19045.7725 | 10.0.19045.7725 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.9512 | 10.0.14393.9512 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.9245 | 10.0.17763.9245 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.7725 | 10.0.19044.7725 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.7725 | 10.0.19045.7725 |
| microsoft | windows_11_23h2 | < 10.0.22631.7582 | 10.0.22631.7582 |
| microsoft | windows_11_24h2 | < 10.0.26100.9445 | 10.0.26100.9445 |
| microsoft | windows_11_25h2 | < 10.0.26200.9445 | 10.0.26200.9445 |
| microsoft | windows_11_26h1 | < 10.0.28000.2954 | 10.0.28000.2954 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.7582 | 10.0.22631.7582 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.9445 | 10.0.26100.9445 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.9445 | 10.0.26200.9445 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2954 | 10.0.28000.2954 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.26349 | 6.2.9200.26349 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.23398 | 6.3.9600.23398 |
| microsoft | windows_server_2016 | < 10.0.14393.9512 | 10.0.14393.9512 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.9512 | 10.0.14393.9512 |
| microsoft | windows_server_2019 | < 10.0.17763.9245 | 10.0.17763.9245 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.9245 | 10.0.17763.9245 |
| microsoft | windows_server_2022 | < 10.0.20348.5622 | 10.0.20348.5622 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.5622 | 10.0.20348.5622 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Sans Isc
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
blogs_sans_isc·2026-09-08·CVSS 7.8
CVE-2026-81963 [HIGH] September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
September 2026 Microsoft Patch Tuesday
Published: 2026-09-08. Last Updated: 2026-09-08 19:20:30 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
A few vulnerabilities worth mentioning:
Windows Update Stack Elevation of Privilege Vulnerability (CVE-2026-81963)
Microsoft reports that CVE-2026-81963 is being exploited, though it was not publicly disclosed b
Rapid7
Patch Tuesday - September 2026
blogs_rapid7·2026-09-08·CVSS 7.8
CVE-2026-85880 [HIGH] Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
## Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the batt
Wiz
CVE-2025-69321 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2025-69321 [HIGH] CVE-2025-69321 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69321 :
WordPress vulnerability analysis and mitigation
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Spa grandspa allows Reflected XSS.This issue affects Grand Spa: from n/a through <= 3.5.5.
Source : NVD
## 7.1
Score
Published January 22, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
grandspa
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Wo
2026-09-08
Published