Diaries

Published: 2026-09-09

Redtail Payload Analysis [Guest Diary]

[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

Following a RedTail Linux Payload from DShield to Dynamic Analysis

During monitoring of my DShield honeypot, I observed an attacker uploading a collection of Linux executables targeting several processor architectures. The files included ARM, ARM64, i686, RISC-V and x86-64 variants named as part of a RedTail deployment package. Rather than relying only on static indicators or public threat-intelligence results, I extracted the captured payloads from Cowrie and analyzed the x86-64 variant in an isolated malware-analysis environment.

The x86-64 sample analyzed in this article has the following SHA-256 hash:
63be5f38b520b3143732962a5f8fec1f9abd1f483dbc741ed324e58f955dd35e


Dynamic analysis showed that the payload did considerably more than simply execute. It changed its visible process identity, terminated other processes, killed one of the filesystem-monitoring processes used during the experiment, and created a TCP listening socket. A matched pair of pre- and post-execution memory images was also acquired from the Proxmox hypervisor to preserve the malware's runtime state independently of the infected guest.

From Cowrie Upload to Malware Sample

The original files were recovered from the Cowrie download directory on the DShield honeypot and copied into a separate folder named after the event.code on the DShield SIEM “attack-a7fc773a9f1a”. The attack delivered multiple architecture-specific versions of the same malware family together with shell scripts responsible for deployment and cleanup.


The recovered set included variants for:

The associated deployment script inspected the host architecture and selected the appropriate RedTail executable. Static inspection of the x86-64 binary identified it as a statically linked ELF executable. Strings extracted from the sample also contained an indication that it had been processed with the UPX executable packer.


For the controlled experiment described here, I selected redtail.x86_64, matching the architecture of the Ubuntu analysis VM.

Isolated Analysis Environment

The malware was executed inside an Ubuntu 24.04 virtual machine hosted on Proxmox. The victim was assigned:
10.66.66.10/24

and was connected only to an isolated malware-analysis network.

An INetSim server at:

10.66.66.2
provided simulated network services. The victim had no default route to the Internet. Before execution, connectivity to INetSim was verified while attempts to reach an external address such as 8.8.8.8 returned Network is unreachable.


This design allowed the malware to encounter DNS and network services without allowing it to communicate with real external infrastructure.

Several monitoring mechanisms were started before staging the sample. These included auditd syscall and filesystem rules, inotifywait filesystem monitoring, continuous process and socket sampling, journal and kernel logging, tcpdump on both the victim and INetSim systems, and strace around the actual malware execution.

In addition, guest memory was acquired from outside the infected system using QEMU's dump-guest-memory functionality on the Proxmox host.

Detonating the redtail.x86_64 Elf executable only (Setup.sh and Clean.sh were not ran)

There were three runs (Run 001.1, Run 001.2 and Run 002) of the malware detonation executed, with the VM reverted back to original pre-detonation state between RUN 001 and RUN 002. In RUN 001, the malware file was detonated twice. RUN 001 was run as user privileges but RUN 002 was run as root.

This report will focus on analyzing RUN 002 with comparisons made to RUN 001.1 and 1.2 to establish similiarities and differences between the runs.

Analysing Run 002, two memory images were collected:

vm610-baseline-pre-redtail.elf
vm610-post-redtail.elf

Both images were approximately 6 GB and were independently SHA-256 verified after acquisition. The baseline image was collected after all monitoring processes had been started but before the malware was staged, making the two images suitable for later differential analysis.

 

 

 

 

 

 


Controlled Execution

For the second experiment, the malware was executed directly with the argument observed during the earlier investigation:

redtail.x86_64 ssh
strace confirmed successful execution:
execve("/analysis/run-002/sample/redtail.x86_64",
       ["/analysis/run-002/sample/redtail.x86_64", "ssh"],
       ...) = 0

This was important because it established that the subsequent behavior belonged to a successfully executing instance of the recovered Cowrie payload rather than to a failed launch or unrelated process.
Two RedTail-backed processes remained running after execution:

PID 10395
PID 10404

Both /proc/<PID>/exe links resolved to:
/analysis/run-002/sample/redtail.x86_64
and hashing those executable mappings produced the same SHA-256 as the original recovered sample.
Despite this, neither process presented itself as redtail.x86_64.
Instead, both appeared as:

php-fpm: pool www


Process Masquerading

The strace output captured the mechanism RedTail used to alter its visible process name:
prctl(PR_SET_NAME, "php") = 0
The successful return value demonstrates that RedTail deliberately modified its task name.
The result was a process that appeared in ordinary process listings as a legitimate PHP-FPM worker:
php-fpm: pool www
while /proc/<PID>/exe continued to identify the executable as the original RedTail sample.

This creates a useful forensic distinction. A process listing by itself could suggest that PHP-FPM was running on the system, while examining /proc/<PID>/exe and hashing the mapped executable revealed that the apparent PHP process was actually the RedTail binary.

This behavior was also consistent with an earlier experimental run in which surviving RedTail processes presented themselves using a PostgreSQL-like process name. The repeated observation suggests that RedTail uses legitimate-looking service names to make malicious processes less conspicuous in routine process inspection.

Process Termination and Monitoring Interference

One of the clearest behavioral findings from Run 002 was RedTail's use of SIGKILL.
Before execution, the automated readiness check confirmed that the filesystem-monitoring process was active:   

[OK] inotify PID 1199

During malware execution, strace recorded:

kill(1199, SIGKILL) = 0
The return value of zero indicates that the signal was successfully delivered.
After execution, the same readiness check reported:
[!!] inotify not running

This provides a direct evidence chain:

inotifywait running
        ↓
RedTail calls kill(1199, SIGKILL)
        ↓
kernel reports success
        ↓
inotifywait no longer running

RedTail also issued successful SIGKILL calls against several additional PIDs during the same execution.

An important limitation must be stated here: Run 002 executed RedTail with root privileges. This gave the malware sufficient permission to terminate the root-owned monitoring process. In the earlier Run 001 experiment, a lower-privileged RedTail process attempted to terminate a root-owned monitor but received EPERM. Therefore, the successful termination observed in Run 002 demonstrates RedTail's process-killing behavior, while the ability to kill the monitoring process specifically depended on the privileges under which the sample was executed.

Network Activity, Listener, and INetSim Observations
After execution, surviving RedTail process PID 10395 was observed listening on 0.0.0.0:39983

Although the process appeared as php-fpm: pool www, /proc/10395/exe resolved to the analyzed redtail.x86_64 sample. No packets involving TCP/39983 were observed in the Run 002 victim PCAP, so the purpose of the listening socket could not be determined.  


While INetSim and packet capture initially showed no obvious RedTail outbound traffic, auditd revealed that PID 10395 attempted multiple external connect() calls on TCP port 853. Destinations included 1.1.1.1, 1.0.0.1, 8.8.8.8, 8.8.4.4, 9.9.9.9, 9.9.9.10, and several additional addresses. TCP/853 is commonly associated with DNS-over-TLS, and most of the observed destinations were public DNS resolver infrastructure.

Two addresses, 80.152.203.134 and 109.91.184.21, did not clearly correspond to known public resolver services during the investigation. Reverse-DNS information showed that 80.152.203.134 resolved to mail3.kekew.info and was allocated to Deutsche Telekom AG (AS3320), while 109.91.184.21 resolved to ip-109-091-184-021.um37.pools.vodafone-ip.de and belonged to a Vodafone GmbH static B2B customer pool (AS3209). Both addresses were contacted by the same RedTail-backed process on TCP/853, with the connection attempts failing with ENETUNREACH. Their specific role in the observed activity could therefore not be confirmed, and they were retained as anomalous resolver candidates rather than classified as malicious infrastructure.


Because the victim was deliberately configured without a default Internet route, every external connection attempt failed with ENETUNREACH before a packet could leave the host. This explains why these attempts were absent from both the victim PCAP and INetSim logs. In this case, endpoint auditing revealed network intent that network monitoring alone could not observe.

Differential analysis of the pre- and post-execution memory images also found several of the TCP/853 destinations only in post-execution memory. However, examination of the surrounding RAM showed that these strings belonged to cached audit records containing the RedTail PID, executable path, destination address and failed connect() result. The memory findings therefore corroborated the auditd evidence but were not treated as proof that RedTail stored its resolver list directly in plaintext process memory.




The same TCP/853 resolver sequence was reproduced in both separate RedTail executions. Several destinations corresponded to established DNS-over-TLS services, strongly supporting the interpretation that this sequence forms part of RedTail's resolver-selection or encrypted DNS initialization behaviour.

A RedTail-backed TCP listener was observed during both executions, but the listening port differed between runs (40219 in Run 001 and 39983 in Run 002). No traffic involving either listener was observed during the corresponding packet captures. This suggests that the listener port may be dynamically selected, although two observations are insufficient to determine the exact selection mechanism.

Filesystem Changes and Persistence

Run 002 provided direct evidence of persistence. Immediately after execution, the RedTail-backed process spawned a shell that first removed the existing root crontab and then installed a new entry containing @reboot <RedTail executable>. The resulting /var/spool/cron/crontabs/root file was absent from the pre-execution filesystem baseline but present following execution. This established a straightforward reboot-persistence mechanism: RedTail would be relaunched whenever the infected host restarted.






RedTail also spawned a separate shell that invoked iptables -F and attempted to insert an INPUT rule allowing TCP traffic to port 39983. This was the same port on which the surviving masqueraded RedTail process was listening. The behavior therefore suggests that RedTail attempted to expose its newly created listener through the host firewall. Audit and process-accounting evidence confirm that both iptables commands were executed as root; however, because no post-execution firewall ruleset or command termination status was preserved, successful application of the firewall changes could not be independently verified.





Run 001 showed the same persistence and firewall logic while RedTail was executed as the unprivileged victor58 account. Instead of creating a root crontab, RedTail removed and replaced the current user's crontab, resulting in the creation of /var/spool/cron/crontabs/victor58 with an @reboot entry pointing to the RedTail executable. This demonstrates that the cron persistence mechanism does not depend on root privileges; RedTail installs persistence under whichever account is executing the malware. Run 001 contained two separate executions of the sample, and each execution repeated this behavior. The corresponding firewall commands attempted to flush the ruleset and allow inbound access to the dynamically selected listener ports 39539 and 40219. Because these commands were executed as UID 1000 without root privileges, successful firewall modification was not established and would normally require additional privileges.




Across the two runs, the persistence behavior was therefore consistent while the resulting crontab depended on execution context: Run 001 persisted through the victor58 user crontab, whereas Run 002 persisted through the root crontab. The listener ports also differed across executions (39539, 40219, and 39983), further supporting the observation that RedTail selects a high-numbered listening port dynamically rather than relying on a single fixed port.

Process Masquerading and Listener Establishment

RedTail established a high-numbered TCP listener while disguising its process identity. During the first Run 001 execution, RedTail changed its process name to php, and the surviving malware process, PID 147999, was subsequently observed listening on 0.0.0.0:39539. Audit records from the same execution showed a child process invoking iptables -I INPUT -p tcp --dport 39539 -j ACCEPT, directly linking the firewall-modification attempt to the dynamically selected listener port. The iptables executable was successfully launched, although the preserved evidence does not confirm that the non-root process successfully applied the firewall rule.

The behaviour was reproduced with different values across subsequent executions. The second Run 001 execution masqueraded using a PostgreSQL-like process name and listened on TCP port 40219, while the root-privileged Run 002 execution used the process name php, a php-fpm: pool www process title, and listened on TCP port 39983. The differing ports across the three executions indicate dynamic high-port selection rather than reliance on a fixed listening port. In each case, RedTail's firewall command referenced the corresponding selected listener port.

RUN 001.1 Pictures


RUN 001.2 Pictures

RUN 002 Pictures



Summary

Host Discovery and System Profiling

Immediately after execution, RedTail performed extensive host profiling through Linux /proc and /sys interfaces. It queried processor characteristics, CPU topology and cache configuration, system memory, NUMA layout, huge-page availability, GPU information, kernel boot parameters, and DMI hardware identifiers.

Several of these queries were capable of identifying the analysis environment as virtualized. In Run 002, the returned data included the hypervisor CPU flag, QEMU system and chassis vendor values, SeaBIOS, and a Q35 virtual-machine product identifier. Despite receiving these virtualization indicators, RedTail continued executing its persistence, listener-creation and network-initialization routines.

To determine whether this profiling was incidental or part of a consistent initialization routine, the same query set was compared across both RedTail executions in Run 001 and the root-privileged execution in Run 002.

Raw Log Screenshot Snippets



Processed Logs Screenshot Snippet

RedTail Host Profiling Queries — Run 002

RedTail first queried /proc/cpuinfo and /proc/cmdline, obtaining processor, architecture and kernel information. The CPU information identified the virtual machine as exposing an AMD Ryzen 7 6800H processor with four visible CPUs and included the hypervisor CPU flag.

The sample then enumerated the topology of CPUs 0 through 3. It queried core IDs, CPU maps, package and die relationships, and CPU availability. This allowed it to identify the number and arrangement of available processors.

RedTail also performed unusually detailed cache enumeration. It queried the type, level, size, line size, number of sets, and sharing relationships of the available L1, L2 and L3 caches. It continued checking additional cache indexes until the kernel returned ENOENT, indicating that no further cache levels were present.

This behaviour shows that RedTail was not limited to simply determining the processor model or CPU count. It collected detailed information about the resources and topology available to the process.

CPU topology

CPU cache profiling

NUMA and memory profiling

RedTail queried /proc/meminfo to determine total and available system memory, swap configuration and huge-page availability. In Run 002, the VM exposed approximately 6 GB of RAM and 4 GB of swap, while no huge pages were currently allocated.

The sample also queried NUMA information under /sys/devices/system/node. It identified a single NUMA node, obtained the CPUs associated with that node, examined node-specific memory usage, and checked both 2 MB and 1 GB huge-page configurations. RedTail additionally attempted to query NUMA bandwidth and latency interfaces, although these returned ENOENT because the interfaces were unavailable in the VM.

The detailed CPU, cache, NUMA and huge-page enumeration resemble resource-suitability profiling that could be useful to a computationally intensive workload. However, the observed system calls 
alone do not establish exactly how RedTail used this information.

Hardware and virtualization profiling

RedTail queried multiple DMI identifiers under /sys/devices/virtual/dmi/id/. It also retrieved the VM's product_uuid when executing with root privileges.

These results show that RedTail queried information sufficient to identify the system as a QEMU virtual machine. The evidence does not establish that the malware performed anti-VM evasion or terminated based on these values; in this experiment, it continued execution despite receiving them.

Host Profiling Comparison Across Run 001 and Run 002

The host-profiling behaviour was highly reproducible.
Run 001 contained two separate non-root executions of RedTail, and each produced 180 extracted host query/reply records. Run 002 executed the same sample as root. After normalizing the process-specific /proc/<PID>/cpuset path, the unique host-information query sets from all three executions were identical and produced the same SHA-256 hash.

This demonstrated that RedTail consistently queried the same categories of information across all three executions:

• CPU and processor capabilities
• CPU topology
• cache configuration
• system memory
• NUMA topology
• huge-page configuration
• GPU information
• kernel configuration
• DMI hardware and virtualization identifiers

1. Identify which Run 001 trace files performed the host profiling

2. Extract PATH | REPLY from every matching RedTail trace

3. Then list what was created:

4. Make a clean list of only the paths queried

5. Compare the two Run 001 executions

6. Compare Run 001 with Run 002

Create its path-only version for Run 002, same formatting as applied to Run 001:

Then compare it against Run 001:

7. Normalizing the process-specific /proc/<PID>/cpuset pathname

8. Comparing all 3 runs query paths again with sha256 hashes of the files.

Result: All the same query paths being run.

After which, a comparison of the returned values was performed. A comparison was taken between the two non-root Run 001 executions:

The comparison of the returned values showed that most differences were simply caused by changing system state. For example, free and available memory differed between executions while the same /proc/meminfo query was performed each time.

The comparison between Run 001 and Run 002 were more interesting because Run 001 was non-root while Run 002 was root directly, the differences were related to execution privilege. During the non-root Run 001 executions, the following DMI queries returned EACCES:

chassis_serial | ERROR: EACCES
product_serial | ERROR: EACCES
product_uuid   | ERROR: EACCES

During root-privileged Run 002, RedTail queried exactly the same paths, but access succeeded:

chassis_serial | [empty]
product_serial | [empty]
product_uuid   | 770cb473-61eb-4f56-9777-d9e44d8ad48f

The second Run 001 execution gives the same non-root result, strengthening the finding.


This suggests that RedTail did not adapt its discovery routine according to privilege. Instead, it attempted the same enumeration sequence and obtained additional information when its execution context permitted access.

Root Privileges Query Output (No error returned):

Profiling Summary

The analysis showed that host and resource profiling is a consistent part of RedTail's initialization behaviour. Across three separate executions—two non-root executions in Run 001 and one root execution in Run 002—the malware queried an identical normalized set of host-information paths.

RedTail collected considerably more information than was required simply to identify the operating system. It enumerated CPU topology and cache geometry, system and NUMA memory, huge-page configuration, GPU availability, kernel parameters and DMI hardware identifiers. Execution privilege affected what information the operating system returned, but not which resources RedTail attempted to query.

Across all executions, RedTail obtained clear indicators that the analysis host was virtualized, including the hypervisor CPU flag, QEMU vendor strings, SeaBIOS and the Q35 virtual-machine identifier. Despite receiving these signals, the sample continued with cron persistence, listener creation, firewall-manipulation attempts and network initialization. This suggests that obvious virtualization indicators alone were not sufficient to alter or halt RedTail’s observed runtime behaviour. One possible explanation is that virtualization by itself is no longer a reliable indicator of a malware-analysis sandbox, because similar characteristics are also common in legitimate VPS and cloud-hosted Linux environments. The purpose of these virtualization-related queries therefore cannot be conclusively attributed to sandbox evasion.

Process Termination and Defense Evasion

During Run 002, RedTail enumerated running processes through /proc, resolved their executable paths, and inspected command-line arguments before selectively issuing SIGKILL. The malware successfully terminated PID 1199, an inotifywait process used by the analysis environment to monitor filesystem changes. It also successfully killed the timeout process supervising the tracing session, along with two sudo processes associated with the script used to launch the experiment. In each of these cases, the kill() system call returned 0, confirming that the termination request succeeded.

RedTail also identified /usr/bin/strace, read the command line showing that it was tracing the RedTail executable, and then issued SIGKILL against the strace process. The trace terminated while recording this system call, so its return value was not preserved. Nevertheless, the sequence provides strong evidence that RedTail actively interfered with the instrumentation used to observe its behaviour during the root-privileged execution. The available dynamic evidence confirms analysis-tool disruption, although it does not yet establish the exact criteria RedTail used to decide which processes to terminate.



The same process-enumeration and termination behaviour was reproduced during the two non-root executions in Run 001. In both executions, RedTail identified the root-owned inotifywait process used to monitor filesystem changes, read its command line, and attempted to terminate it with SIGKILL. These attempts returned EPERM, demonstrating that the non-root execution context prevented RedTail from terminating the root-owned monitor.


Process terminated as Root:

However, non-root privileges did not prevent RedTail from interfering with analysis processes running under the same user context. During the second Run 001 execution, RedTail identified and successfully terminated the timeout process supervising its strace session. It then identified /usr/bin/strace, read the command line showing that the tracer was monitoring the RedTail executable, and invoked SIGKILL; the trace terminated before the system-call return value could be recorded. The second execution also successfully terminated PID 147999, the surviving RedTail process from the first execution, suggesting possible previous-instance cleanup or single-instance enforcement.

Process terminated as User:


Together, Runs 001 and 002 show that RedTail's process-disruption routine operates regardless of privilege, while its effectiveness depends on the ownership and privilege level of the target process. Root execution enabled RedTail to terminate the root-owned filesystem monitor, whereas non-root execution was restricted to processes it was permitted to signal.

Overall Conclusion

Dynamic analysis of the RedTail sample revealed a consistent sequence of host discovery, persistence, process manipulation, network initialization, and defensive interference across both privileged and unprivileged executions. Although individual values such as process names and listening ports changed between executions, the underlying behavior was highly reproducible.

RedTail performed extensive host profiling through Linux /proc and /sys interfaces, enumerating processor characteristics, cache topology, memory, NUMA configuration, huge-page availability, and DMI hardware information. The same normalized set of host-information paths was queried across both Run 001 executions and Run 002. The sample also obtained explicit virtualization indicators, including the hypervisor CPU flag, QEMU identifiers, SeaBIOS, and a Q35 virtual-machine product name, but continued execution despite receiving this information. Execution privilege affected the information available to the malware but did not substantially alter its discovery routine.

Persistence was established through the current execution account's crontab using an @reboot entry pointing to the RedTail executable. Consequently, the non-root Run 001 execution created persistence for victor58, while the root-privileged Run 002 execution created root-level cron persistence. RedTail also attempted to manipulate the host firewall by flushing existing rules and inserting an INPUT rule for its dynamically selected TCP listener. The selected listener changed between executions—TCP ports 39539, 40219, and 39983 were observed—while the corresponding iptables command referenced the matching port in each case. Firewall modification was confirmed as attempted, although the preserved evidence does not establish successful rule application in every execution.

RedTail additionally disguised its running processes. Observed process names included php and a PostgreSQL-like postgres: user ..., while Run 002 also presented a process title of php-fpm: pool www despite the executable remaining redtail.x86_64. The masquerading processes owned the dynamically selected TCP listeners, demonstrating that the altered identities were associated with the surviving malware processes rather than unrelated applications.

A particularly significant finding was RedTail's interference with the analysis environment. The malware enumerated running processes, inspected executable paths and command-line arguments, and selectively issued SIGKILL. During non-root Run 001, attempts to terminate the root-owned inotifywait filesystem monitor failed with EPERM; however, RedTail remained capable of disrupting analysis processes that it had permission to signal, including the timeout process supervising its tracing session. During root-privileged Run 002, the same inotifywait monitor was successfully terminated. RedTail also identified /usr/bin/strace, read the command line showing that it was tracing redtail.x86_64, and issued SIGKILL; the trace terminated while recording that operation. These observations demonstrate that the process-disruption routine was present regardless of privilege, while its effectiveness depended on the privileges and ownership of the target process.

Network analysis identified repeated connection attempts to multiple external IP addresses on TCP port 853. The same target sequence appeared across Run 001 and Run 002, supporting its association with RedTail rather than unrelated host activity. Because the analysis VM deliberately had no default Internet route, these connections failed with ENETUNREACH and did not leave the host. The use of TCP/853 is consistent with DNS-over-TLS infrastructure, although the isolated environment prevented observation of any successful protocol exchange and therefore does not establish the ultimate purpose of those connections.

Static examination of the accompanying clean.sh script identified additional cleanup functionality targeting cron entries, shell-startup files, temporary directories, miner-related services, and suspicious process names. However, the script was not observed executing during either dynamic-analysis run. Its functionality should therefore be treated separately from behavior directly demonstrated by redtail.x86_64.

Overall, the experiments show RedTail as a Linux threat that combines persistent execution, extensive host profiling, process masquerading, dynamically selected listening services, attempted firewall manipulation, repeated external network initialization, and active interference with monitoring and analysis processes. Running the sample under both non-root and root contexts was particularly valuable: the experiments demonstrated that RedTail largely follows the same behavioral sequence regardless of privilege, while elevated privileges substantially increase the effectiveness of actions such as accessing protected host identifiers, modifying privileged resources, and terminating root-owned monitoring processes.

Limitations of Analysis:

• External TCP/853 connections could not complete because the victim intentionally had no Internet route.
• No inbound interaction with the RedTail listeners was observed, so their higher-level protocol/function was not established.
• Successful execution of iptables via execve() does not by itself prove that every firewall-rule change was successfully applied.
clean.sh and setup.sh was analyzed statically and was not observed executing during Runs 001 or 002.

Indicators of Compromise

MITRE ATT&CK Mapping

Other Summary Findings – Supporting RedTail File Deployment and Clean Up

Static Analysis of SETUP.SH *Not Executed in any of the runs*

Static examination of setup.sh identified a multi-architecture staging and execution mechanism for RedTail. The script determines the victim's processor architecture and selects an associated payload for x86-64, x86, ARM or RISC-V systems. It enumerates user-owned writable directories and examines filesystem noexec settings to identify a suitable staging location, with /tmp, /var/tmp and /dev/shm included as fallback locations. The selected RedTail binary is copied into a randomly generated dot-prefixed filename, marked executable and launched with the argument ssh. Following execution, the script deletes the more readily identifiable redtail.* architecture-specific payload files from both the staging and original directories. This combination of malware relocation, hidden-file staging and artifact cleanup appears intended to reduce the visibility of the deployed executable. Static analysis does not, by itself, establish that setup.sh executed during the controlled dynamic-analysis runs.

Static Analysis of CLEAN.SH *Not Executed in any of the runs*

Static analysis of the accompanying clean.sh script revealed functionality designed to remove common Linux malware persistence mechanisms and terminate suspicious processes. The script first disables and stops a service named c3pool_miner. It then removes immutable and append-only attributes from cron files before filtering user and system cron configurations for commands containing strings such as wget, curl, /dev/tcp, /tmp, .sh, nc, bash -i, sh -i, and base64 -d.

The cleanup extends across user crontabs, /etc/crontab, cron scheduling directories, /etc/anacrontab, and the current user's crontab. The script additionally removes the top-level contents of /tmp, /var/tmp, and /dev/shm, and applies the same filtering routine to .bashrc, .bash_profile, and .profile. These actions are consistent with an attempt to remove scheduled-task, shell-startup, and temporary-file persistence.

Finally, the script attempts to terminate processes associated with unusual names including /bin/-bash, systemtd, and /usr/bin/.sh using SIGKILL. The name systemtd resembles the legitimate systemd service name and may represent an attempt to target a masquerading process. However, the available evidence does not establish that these filenames belong specifically to the RedTail sample analyzed in Runs 001 and 002.

The script was not observed executing during either dynamic-analysis run. Its contents should therefore be treated as static functionality associated with the recovered script rather than behaviour directly observed from redtail.x86_64.

SETUP.SH File Contents


CLEAN.SH File Contents

[1] https://www.inetsim.org/index.html
[2] https://github.com/bruneaug/DShield-SIEM/tree/main
[3] https://www.sans.edu/cyber-security-programs/bachelors-degree/

-----------
Guy Bruneau IPSS Inc.
My GitHub Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu

0 Comments

Published: 2026-09-09

Scans for Proxmox Servers

About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.

But it appears that the vulnerability may have caught the attention of some attackers and researchers. We do see a bump in scans for port 8006, and also some additional brute force traffic. For example, brute force requests like:

POST /api2/json/access/ticket HTTP/1.1
Host: [redacted]:8006
User-Agent: Go-http-client/1.1
Content-Length: 37
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

 

password=Ww778899&username=root%40pam

The PVE proxy log will log failed login attempts with a 401 status code:

::ffff:62.60.130.193 - - [09/09/2026:15:26:14 +0000] "POST /api2/json/access/ticket HTTP/1.1" 401 50
::ffff:62.60.130.193 - - [09/09/2026:15:28:04 +0000] "POST /api2/json/access/ticket HTTP/1.1" 308 18
::ffff:62.60.130.193 - - [09/09/2026:15:28:08 +0000] "POST /api2/json/access/ticket HTTP/1.1" 401 50
::ffff:62.60.130.193 - - [09/09/2026:15:29:49 +0000] "POST /api2/json/access/ticket HTTP/1.1" 308 18
::ffff:62.60.130.193 - - [09/09/2026:15:29:52 +0000] "POST /api2/json/access/ticket HTTP/1.1" 401 50
::ffff:62.60.130.193 - - [09/09/2026:15:31:33 +0000] "POST /api2/json/access/ticket HTTP/1.1" 308 18
::ffff:62.60.130.193 - - [09/09/2026:15:31:36 +0000] "POST /api2/json/access/ticket HTTP/1.1" 401 50

You may also see the less commonly used 308 status code if the attacker does not use TLS on their first attempt and instead sends a POST request (as shown above). A 308 access code allows a client to change the request method after following the redirect. 301 and 302 status codes require the same method for the follow-up request.

Other scans I have seen:

Classic Fingerprinting

/pve2/images/logo-128.png???????

And a POST request to /api2/extjs/access/ticket. This endpoint behaves differently from the prior endpoint. It always returns 200, but the JSON payload will contain the login failed messages. These are trickier to analyze because the proxy log does not indicate the outcome of authentication. A return payload size of 77 bytes should indicate failure.

 

--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

0 Comments

Published: 2026-09-08

September 2026 Microsoft Patch Tuesday

This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

A few vulnerabilities worth mentioning:

Windows Update Stack Elevation of Privilege Vulnerability (CVE-2026-81963)
Microsoft reports that CVE-2026-81963 is being exploited, though it was not publicly disclosed before Patch Tuesday. This Important-severity Windows Update Stack elevation of privilege vulnerability has a CVSS score of 7.8 and affects Windows 11 and Windows Server 2025 systems. The flaw involves improper link resolution before file access, allowing a local, authenticated attacker with low privileges to abuse link-following behavior and elevate to SYSTEM privileges. Administrators should prioritize applying the Windows security updates for affected Windows 11 and Windows Server 2025 systems, including Server Core installations.

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability (CVE-2026-85880)
Microsoft lists CVE-2026-85880 as exploited in the wild, although it was not publicly disclosed before Patch Tuesday and is not currently in CISA’s Known Exploited Vulnerabilities catalogue. This Important-severity Windows ALPC elevation of privilege vulnerability has a CVSS score of 7.8 and affects Windows 10 and multiple Windows Server releases, including Server 2012, 2016, 2019, and 2022. The flaw is a heap-based buffer overflow that can be exploited locally by an attacker who can run code in a low-privilege AppContainer; no user interaction is required. Successful exploitation allows the attacker to escape the sandbox and gain SYSTEM privileges on the affected host. Given Microsoft’s exploited-in-the-wild assessment, prioritize deployment of the applicable Windows security updates, especially on multi-user systems, exposed workstations, and servers where local code execution paths are available.

Skype for Business Remote Code Execution Vulnerability (CVE-2026-66302)
Microsoft reports that CVE-2026-66302 is not being exploited in the wild and was not publicly disclosed before Patch Tuesday. This is a Critical remote code execution vulnerability in Skype for Business Server with a CVSS score of 9.8, affecting Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1. The flaw involves external control of a file name or path, allowing an unauthenticated attacker to send a specially crafted network request that writes an attacker-controlled file to an arbitrary location on the affected server; successful exploitation could allow code execution on the target server without authentication or user interaction. Administrators should prioritize applying Microsoft’s updates for affected Skype for Business Server installations and review exposed deployments, logging, and access controls for signs of suspicious file writes or unexpected server-side code execution.

Windows Message Queuing Remote Code Execution Vulnerability (CVE-2026-69579)
Microsoft reports that CVE-2026-69579 is not known to be exploited in the wild and was not publicly disclosed before Patch Tuesday. This Critical remote code execution vulnerability carries a CVSS score of 9.8 and is a use-after-free flaw in Windows Message Queuing affecting supported Windows client and server releases. An unauthenticated attacker could exploit it remotely by sending a specially crafted packet to an affected Message Queuing service, with no user interaction required, potentially allowing code execution on the target system with high impact to confidentiality, integrity, and availability. Systems running MSMQ should be prioritized for patching; where Message Queuing is not needed, disabling the service or restricting network access to it, including limiting exposure of MSMQ traffic such as TCP port 1801, can reduce risk until updates are applied.

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVE-2026-69590)
CVE-2026-69590 is not listed by Microsoft as exploited in the wild and has not been publicly disclosed; it is a Critical remote code execution vulnerability in Windows RRAS with a CVSS score of 9.8. An unauthenticated remote attacker could exploit the flaw by sending a specially crafted packet to an affected RRAS service over the network, with no user interaction required, potentially allowing code execution on the target system with serious confidentiality, integrity, and availability impact. Affected platforms include supported Windows 10, Windows 11, and Windows Server releases. Organizations should apply the Microsoft security update promptly, especially on systems running RRAS, and reduce exposure by disabling RRAS where it is not needed, restricting network access to the service with firewalls or VPN controls, and monitoring for unexpected traffic to RRAS-enabled hosts.

This was a summary of Microsoft’s monthly updates highlighting key vulnerabilities. Prioritize the exploited Important Windows EOP flaws, CVE-2026-81963 and CVE-2026-85880, then patch exposed Skype for Business, MSMQ, and RRAS systems vulnerable to Critical unauthenticated RCE.

A detailed list of this month's vulnerabilities follows below. To search and filter them, visit my dashboard: https://patchlens.io

Description
CVE Disclosed Exploited Exploitability (old versions) current version Severity CVSS Base (AVG) CVSS Temporal (AVG)
.NET Elevation of Privilege Vulnerability
%%cve:2026-69805%% No No - - Important 7.5 6.5
%%cve:2026-69806%% No No - - Important 7.0 6.1
.NET Information Disclosure Vulnerability
%%cve:2026-58649%% No No - - Important 6.5 5.7
.NET and Visual Studio Elevation of Privilege Vulnerability
%%cve:2026-69439%% No No - - Important 8.8 7.7
.NET and Visual Studio Remote Code Execution Vulnerability
%%cve:2026-69522%% No No - - Important 8.8 7.7
%%cve:2026-71328%% No No - - Important 8.8 7.7
ASP.NET Core Denial of Service Vulnerability
%%cve:2026-57099%% No No - - Important 7.5 6.5
%%cve:2026-69304%% No No - - Important 5.9 5.2
Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability
%%cve:2026-62810%% No No - - Important 7.8 6.8
%%cve:2026-69821%% No No - - Important 7.8 6.8
Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability
%%cve:2026-69395%% No No - - Important 6.5 5.7
Active Directory Certificate Services (AD CS) Tampering Vulnerability
%%cve:2026-69624%% No No - - Important 6.5 5.7
Active Directory Domain Services Elevation of Privilege Vulnerability
%%cve:2026-69359%% No No - - Important 7.8 6.8
Active Directory Federation Services (AD FS) Denial of Service Vulnerability
%%cve:2026-72978%% No No - - Important 5.9 5.2
Audio Video Control Transport Protocol Elevation of Privilege Vulnerability
%%cve:2026-69401%% No No - - Important 7.0 6.1
Azure AI Language Elevation of Privilege Vulnerability
(no customer action required)
%%cve:2026-70352%% No No - - Critical 10.0 8.7
Azure Arc SQL Server Extension Elevation of Privilege Vulnerability
%%cve:2026-62895%% No No - - Important 8.8 7.7
Azure Cosmos DB Spoofing Vulnerability
(no customer action required)
%%cve:2026-69857%% No No - - Critical 8.5 7.4
Azure CycleCloud Information Disclosure Vulnerability
%%cve:2026-77909%% No No - - Important 7.7 6.7
Azure HDInsight Ambari Elevation of Privilege Vulnerability
%%cve:2026-81349%% No No - - Important 7.2 6.5
BranchCache Denial of Service Vulnerability
%%cve:2026-69329%% No No - - Important 7.5 6.5
Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability
%%cve:2026-69516%% No No - - Important 7.0 6.1
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
%%cve:2026-68824%% No No - - Important 7.0 6.1
%%cve:2026-68847%% No No - - Important 7.0 6.1
%%cve:2026-69470%% No No - - Important 7.0 6.1
%%cve:2026-69625%% No No - - Important 8.0 7.0
Copilot Studio Elevation of Privilege Vulnerability
(no customer action required)
%%cve:2026-80098%% No No - - Critical 9.3 8.1
Data Sharing Service Client Elevation of Privilege Vulnerability
%%cve:2026-73014%% No No - - Important 7.8 6.8
DirectWrite Remote Code Execution Vulnerability
%%cve:2026-73006%% No No - - Critical 8.8 7.7
%%cve:2026-73016%% No No - - Important 8.8 7.7
Entra ID Elevation of Privilege Vulnerability
(no customer action required)
%%cve:2026-83941%% No No - - Critical 9.9 8.6
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
%%cve:2026-81380%% No No - - Important 5.3 4.6
%%cve:2026-81381%% No No - - Important 6.5 5.7
Graphic Fonts Elevation of Privilege Vulnerability
%%cve:2026-69576%% No No - - Important 7.8 6.8
Graphic Fonts Remote Code Execution Vulnerability
%%cve:2026-72986%% No No - - Critical 8.8 7.7
%%cve:2026-73018%% No No - - Critical 8.8 7.7
Graphics Kernel Remote Code Execution Vulnerability
%%cve:2026-73017%% No No - - Critical 7.5 6.5
HEIF Image Extensions Remote Code Execution Vulnerability
%%cve:2026-81353%% No No - - Important 7.8 6.8
HEVC Video Extensions Elevation of Privilege Vulnerability
%%cve:2026-58600%% No No - - Important 7.8 6.8
HEVC Video Extensions Remote Code Execution Vulnerability
%%cve:2026-58599%% No No - - Critical 7.8 6.8
HID Class Driver Elevation of Privilege Vulnerability
%%cve:2026-69731%% No No - - Important 7.8 6.8
IP Helper Remote Code Execution Vulnerability
%%cve:2026-72981%% No No - - Critical 8.1 7.1
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
%%cve:2026-72983%% No No - - Critical 9.8 8.5
Internet Storage Name Service Information Disclosure Vulnerability
%%cve:2026-68895%% No No - - Important 5.5 4.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
%%cve:2026-69275%% No No - - Important 7.0 6.1
%%cve:2026-69900%% No No - - Important 7.8 6.8
Microsoft Account Elevation of Privilege Vulnerability
%%cve:2026-68850%% No No - - Important 7.8 6.8
Microsoft Account Information Disclosure Vulnerability
%%cve:2026-68852%% No No - - Important 5.5 4.8
Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
%%cve:2026-84003%% No No - - Important 7.4 6.4
Microsoft Authenticator Elevation of Privilege Vulnerability
%%cve:2026-80097%% No No - - Important 8.6 7.5
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
(no customer action required)
%%cve:2026-83711%% No No - - Critical 10.0 8.7
Microsoft Azure CLI Remote Code Execution Vulnerability
%%cve:2026-83948%% No No - - Important 8.0 7.0
Microsoft COM for Windows Elevation of Privilege Vulnerability
%%cve:2026-69299%% No No - - Important 7.0 6.1
Microsoft COM for Windows Information Disclosure Vulnerability
%%cve:2026-69294%% No No - - Important 5.5 4.8
Microsoft DirectMusic Remote Code Execution Vulnerability
%%cve:2026-69491%% No No - - Important 9.8 8.5
Microsoft Discovery Studio Information Disclosure Vulnerability
(no customer action required)
%%cve:2026-62906%% No No - - Critical 7.4 6.4
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
%%cve:2026-65772%% No No - - Critical 8.8 7.7
%%cve:2026-77908%% No No - - Important 8.8 7.7
Microsoft Entra ID Elevation of Privilege Vulnerability
(no customer action required)
%%cve:2026-62916%% No No - - Critical 9.1 7.9
Microsoft Excel Information Disclosure Vulnerability
%%cve:2026-81387%% No No - - Important 5.5 4.8
%%cve:2026-81390%% No No - - Important 5.5 4.8
%%cve:2026-81391%% No No - - Important 5.5 4.8
%%cve:2026-81392%% No No - - Important 5.5 4.8
%%cve:2026-81393%% No No - - Important 5.5 4.8
%%cve:2026-81394%% No No - - Important 5.5 4.8
%%cve:2026-81395%% No No - - Important 5.5 4.8
%%cve:2026-81399%% No No - - Important 5.5 4.8
%%cve:2026-81400%% No No - - Important 5.5 4.8
%%cve:2026-81401%% No No - - Important 5.5 4.8
%%cve:2026-81958%% No No - - Important 5.5 4.8
Microsoft Excel Remote Code Execution Vulnerability
%%cve:2026-81386%% No No - - Important 7.8 6.8
%%cve:2026-81388%% No No - - Important 7.8 6.8
%%cve:2026-81389%% No No - - Important 7.0 6.1
%%cve:2026-81396%% No No - - Important 7.8 6.8
%%cve:2026-81397%% No No - - Important 7.8 6.8
%%cve:2026-81398%% No No - - Important 7.8 6.8
%%cve:2026-81947%% No No - - Important 7.8 6.8
%%cve:2026-81948%% No No - - Critical 7.8 6.8
%%cve:2026-81949%% No No - - Critical 7.8 6.8
%%cve:2026-81950%% No No - - Critical 7.8 6.8
%%cve:2026-81951%% No No - - Critical 7.8 6.8
%%cve:2026-81953%% No No - - Critical 7.8 6.8
%%cve:2026-81954%% No No - - Important 7.8 6.8
%%cve:2026-81956%% No No - - Important 7.8 6.8
%%cve:2026-81957%% No No - - Important 7.8 6.8
%%cve:2026-81959%% No No - - Critical 7.8 6.8
%%cve:2026-81960%% No No - - Important 7.8 6.8
Microsoft Exchange Server Denial of Service Vulnerability
%%cve:2026-69378%% No No - - Important 7.5 6.5
Microsoft Exchange Server Elevation of Privilege Vulnerability
%%cve:2026-69380%% No No - - Important 8.1 7.1
%%cve:2026-69641%% No No - - Important 9.1 7.9
Microsoft Exchange Server Information Disclosure Vulnerability
%%cve:2026-69382%% No No - - Important 5.9 5.2
Microsoft Exchange Server Remote Code Execution Vulnerability
%%cve:2026-55007%% No No - - Important 8.1 7.1
%%cve:2026-69355%% No No - - Important 8.8 7.7
Microsoft Exchange Server Spoofing Vulnerability
%%cve:2026-69356%% No No - - Important 9.3 8.1
%%cve:2026-69361%% No No - - Important 6.5 5.7
Microsoft Exchange Server Tampering Vulnerability
%%cve:2026-69375%% No No - - Important 6.5 5.7
Microsoft Fabric Elevation of Privilege Vulnerability
(no customer action required)
%%cve:2026-70178%% No No - - Critical 8.5 7.4
Microsoft Failover Cluster Remote Code Execution Vulnerability
%%cve:2026-73010%% No No - - Critical 9.8 8.5
%%cve:2026-78444%% No No - - Critical 8.1 7.1
Microsoft Graphics Component Elevation of Privilege Vulnerability
%%cve:2026-69467%% No No - - Important 7.8 6.8
%%cve:2026-83990%% No No - - Important 7.8 6.8
Microsoft Graphics Component Remote Code Execution Vulnerability
%%cve:2026-84000%% No No - - Important 7.8 6.8
Microsoft Install Service Elevation of Privilege Vulnerability
%%cve:2026-69605%% No No - - Important 7.0 6.1
Microsoft JScript Remote Code Execution Vulnerability
%%cve:2026-69325%% No No - - Important 8.1 7.1
%%cve:2026-69438%% No No - - Important 8.1 7.1
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
%%cve:2026-69277%% No No - - Important 7.8 6.8
%%cve:2026-69365%% No No - - Important 8.0 7.0
%%cve:2026-69594%% No No - - Important 7.8 6.8
Microsoft Office Access Remote Code Execution Vulnerability
%%cve:2026-69477%% No No - - Important 7.3 6.4
%%cve:2026-69529%% No No - - Important 8.8 7.7
%%cve:2026-69614%% No No - - Important 8.8 7.7
%%cve:2026-69778%% No No - - Important 8.8 7.7
Microsoft Office Excel Information Disclosure Vulnerability
%%cve:2026-72974%% No No - - Important 6.5 5.7
%%cve:2026-78515%% No No - - Important 6.5 5.7
%%cve:2026-85875%% No No - - Important 5.5 4.8
Microsoft Office Excel Remote Code Execution Vulnerability
%%cve:2026-78518%% No No - - Important 8.8 7.7
Microsoft Office Graphics Component Remote Code Execution Vulnerability
%%cve:2026-78439%% No No - - Critical 8.8 7.7
Microsoft Office Information Disclosure Vulnerability
%%cve:2026-69626%% No No - - Important 6.5 5.7
%%cve:2026-69739%% No No - - Important 6.5 5.7
%%cve:2026-80076%% No No - - Important 6.5 5.7
%%cve:2026-80078%% No No - - Important 6.5 5.7
%%cve:2026-80082%% No No - - Important 6.5 5.7
%%cve:2026-80087%% No No - - Important 6.5 5.7
%%cve:2026-80089%% No No - - Important 6.5 5.7
%%cve:2026-80091%% No No - - Important 6.5 5.7
Microsoft Office Outlook Information Disclosure Vulnerability
%%cve:2026-78520%% No No - - Critical 6.5 5.7
%%cve:2026-80073%% No No - - Important    
%%cve:2026-80084%% No No - - Important 6.5 5.7
Microsoft Office Outlook Remote Code Execution Vulnerability
%%cve:2026-69629%% No No - - Important 8.8 7.7
%%cve:2026-78509%% No No - - Critical 9.8 8.5
%%cve:2026-78519%% No No - - Critical    
%%cve:2026-78525%% No No - - Critical 8.8 7.7
Microsoft Office PowerPoint Information Disclosure Vulnerability
%%cve:2026-72938%% No No - - Important 6.5 5.7
%%cve:2026-72956%% No No - - Important 6.5 5.7
%%cve:2026-72975%% No No - - Important 6.5 5.7
%%cve:2026-72977%% No No - - Important 6.5 5.7
%%cve:2026-78513%% No No - - Important 5.5 4.8
%%cve:2026-80086%% No No - - Important 6.5 5.7
Microsoft Office PowerPoint Remote Code Execution Vulnerability
%%cve:2026-69678%% No No - - Critical 8.8 7.7
%%cve:2026-69767%% No No - - Critical 8.8 7.7
%%cve:2026-69797%% No No - - Critical 8.8 7.7
%%cve:2026-80081%% No No - - Important    
Microsoft Office Publisher Remote Code Execution Vulnerability
%%cve:2026-69742%% No No - - Important 8.8 7.7
%%cve:2026-81385%% No No - - Important 8.8 7.7
Microsoft Office Remote Code Execution Vulnerability
%%cve:2026-69285%% No No - - Critical 8.8 7.7
%%cve:2026-69442%% No No - - Important 8.8 7.7
%%cve:2026-69632%% No No - - Critical 8.8 7.7
%%cve:2026-77898%% No No - - Critical 7.5 6.5
%%cve:2026-78505%% No No - - Critical 8.8 7.7
%%cve:2026-78524%% No No - - Important 8.8 7.7
Microsoft Office SharePoint Elevation of Privilege Vulnerability
%%cve:2026-69464%% No No - - Important 8.8 7.7
%%cve:2026-69716%% No No - - Important 8.8 7.7
Microsoft Office SharePoint Information Disclosure Vulnerability
%%cve:2026-69409%% No No - - Important 6.5 5.7
%%cve:2026-69636%% No No - - Important 6.5 5.7
%%cve:2026-69683%% No No - - Important 6.5 5.7
%%cve:2026-69904%% No No - - Important 3.5 3.1
Microsoft Office SharePoint Remote Code Execution Vulnerability
%%cve:2026-69268%% No No - - Important 8.8 7.7
%%cve:2026-69273%% No No - - Important 8.8 7.7
%%cve:2026-69282%% No No - - Important 8.8 7.7
%%cve:2026-69465%% No No - - Important 8.8 7.7
%%cve:2026-69724%% No No - - Important 8.8 7.7
%%cve:2026-69804%% No No - - Important 7.5 6.5
Microsoft Office SharePoint Spoofing Vulnerability
%%cve:2026-69402%% No No - - Important 7.3 6.4
%%cve:2026-69417%% No No - - Important 7.3 6.4
%%cve:2026-69615%% No No - - Important 3.5 3.1
%%cve:2026-69690%% No No - - Important 4.6 4.0
Microsoft Office Spoofing Vulnerability
%%cve:2026-64918%% No No - - Important 6.5 5.7
Microsoft Office Word Information Disclosure Vulnerability
%%cve:2026-68843%% No No - - Important 5.5 4.8
%%cve:2026-69719%% No No - - Important 6.5 5.7
%%cve:2026-69734%% No No - - Important 6.5 5.7
%%cve:2026-72976%% No No - - Important 5.0 4.4
%%cve:2026-77911%% No No - - Important 6.5 5.7
%%cve:2026-78502%% No No - - Important 6.5 5.7
%%cve:2026-78503%% No No - - Important 6.5 5.7
%%cve:2026-78506%% No No - - Important 5.5 4.8
%%cve:2026-78522%% No No - - Important    
%%cve:2026-80079%% No No - - Important    
%%cve:2026-80088%% No No - - Important 6.5 5.7
%%cve:2026-80090%% No No - - Important 6.5 5.7
%%cve:2026-83949%% No No - - Important 5.5 4.8
%%cve:2026-83951%% No No - - Important 5.5 4.8
Microsoft Office Word Remote Code Execution Vulnerability
%%cve:2026-69360%% No No - - Important 8.8 7.7
%%cve:2026-69556%% No No - - Important 8.8 7.7
%%cve:2026-69671%% No No - - Important 8.8 7.7
%%cve:2026-69686%% No No - - Important 8.8 7.7
%%cve:2026-69722%% No No - - Important 8.8 7.7
%%cve:2026-69759%% No No - - Important 8.8 7.7
%%cve:2026-69764%% No No - - Important 8.8 7.7
%%cve:2026-72972%% No No - - Important 8.8 7.7
%%cve:2026-72973%% No No - - Important 8.8 7.7
%%cve:2026-77504%% No No - - Critical 8.8 7.7
%%cve:2026-77901%% No No - - Important 8.8 7.7
%%cve:2026-78504%% No No - - Important 8.8 7.7
%%cve:2026-78507%% No No - - Important 8.8 7.7
%%cve:2026-78511%% No No - - Important 8.8 7.7
%%cve:2026-78512%% No No - - Important 8.8 7.7
%%cve:2026-78514%% No No - - Important 8.8 7.7
%%cve:2026-78517%% No No - - Important 8.8 7.7
%%cve:2026-78521%% No No - - Important 8.8 7.7
%%cve:2026-78526%% No No - - Important 8.8 7.7
%%cve:2026-80080%% No No - - Important 8.8 7.7
%%cve:2026-80085%% No No - - Important 8.8 7.7
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
%%cve:2026-69397%% No No - - Important 7.5 6.5
Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
%%cve:2026-77897%% No No - - Important 7.0 6.1
Microsoft PowerShell Security Feature Bypass Vulnerability
%%cve:2026-62801%% No No - - Important 6.5 5.7
Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
%%cve:2026-57098%% No No - - Important 7.5 6.5
Microsoft SQL Server Denial of Service Vulnerability
%%cve:2026-67376%% No No - - Important 7.5 6.5
%%cve:2026-67633%% No No - - Important 6.5 5.7
%%cve:2026-67641%% No No - - Important 6.5 5.7
Microsoft SQL Server Elevation of Privilege Vulnerability
%%cve:2026-65669%% No No - - Critical 9.6 8.3
%%cve:2026-66814%% No No - - Important 8.8 7.7
%%cve:2026-66818%% No No - - Important 8.8 7.7
%%cve:2026-66819%% No No - - Important 8.8 7.7
%%cve:2026-67368%% No No - - Important 8.8 7.7
%%cve:2026-67370%% No No - - Important 8.8 7.7
%%cve:2026-67381%% No No - - Important 8.8 7.7
Microsoft SQL Server Information Disclosure Vulnerability
%%cve:2026-67369%% No No - - Important 6.5 5.7
%%cve:2026-67383%% No No - - Important 6.5 5.7
%%cve:2026-67386%% No No - - Important 6.5 5.7
%%cve:2026-67389%% No No - - Important 6.5 5.7
%%cve:2026-67390%% No No - - Important 6.5 5.7
%%cve:2026-67393%% No No - - Important 6.5 5.7
%%cve:2026-67624%% No No - - Important 6.5 5.7
%%cve:2026-67629%% No No - - Important 6.5 5.7
%%cve:2026-67630%% No No - - Important 6.5 5.7
%%cve:2026-67645%% No No - - Important 6.5 5.7
%%cve:2026-67648%% No No - - Important 6.5 5.7
%%cve:2026-68776%% No No - - Important 6.5 5.7
%%cve:2026-68777%% No No - - Important 6.5 5.7
%%cve:2026-68778%% No No - - Important 6.5 5.7
%%cve:2026-68779%% No No - - Important 6.5 5.7
%%cve:2026-68780%% No No - - Important 6.5 5.7
%%cve:2026-68781%% No No - - Important 6.5 5.7
%%cve:2026-68784%% No No - - Important 6.5 5.7
%%cve:2026-69562%% No No - - Important 6.5 5.7
%%cve:2026-73029%% No No - - Important 6.5 5.7
%%cve:2026-77488%% No No - - Important 5.5 4.8
Microsoft SQL Server Remote Code Execution Vulnerability
%%cve:2026-47297%% No No - - Important 8.1 7.1
%%cve:2026-67373%% No No - - Important 8.8 7.7
%%cve:2026-67378%% No No - - Critical 8.5 7.4
%%cve:2026-67379%% No No - - Important 8.5 7.4
%%cve:2026-67380%% No No - - Important 8.8 7.7
%%cve:2026-67384%% No No - - Important 8.8 7.7
%%cve:2026-67385%% No No - - Important 8.8 7.7
%%cve:2026-67388%% No No - - Important 8.8 7.7
%%cve:2026-67631%% No No - - Critical 8.8 7.7
%%cve:2026-67636%% No No - - Critical 8.5 7.4
%%cve:2026-67638%% No No - - Important 8.8 7.7
%%cve:2026-67639%% No No - - Important 8.8 7.7
%%cve:2026-67642%% No No - - Important 8.8 7.7
%%cve:2026-67643%% No No - - Critical 8.8 7.7
%%cve:2026-68775%% No No - - Important 8.8 7.7
%%cve:2026-68785%% No No - - Important 4.9 4.3
%%cve:2026-68786%% No No - - Important 8.8 7.7
%%cve:2026-68787%% No No - - Important 7.8 6.8
%%cve:2026-77481%% No No - - Important 8.8 7.7
%%cve:2026-77482%% No No - - Important 8.8 7.7
%%cve:2026-77484%% No No - - Important 8.8 7.7
%%cve:2026-77486%% No No - - Important 8.8 7.7
Microsoft SQL Server Security Feature Bypass Vulnerability
%%cve:2026-66816%% No No - - Important 6.5 5.7
Microsoft Standard XPS Elevation of Privilege Vulnerability
%%cve:2026-68885%% No No - - Important 7.8 6.8
%%cve:2026-68888%% No No - - Important 7.8 6.8
%%cve:2026-68889%% No No - - Important 7.1 6.2
%%cve:2026-68890%% No No - - Important 7.8 6.8
%%cve:2026-68892%% No No - - Important 7.8 6.8
%%cve:2026-68897%% No No - - Important 7.0 6.1
%%cve:2026-69269%% No No - - Important 7.8 6.8
%%cve:2026-69271%% No No - - Important 8.0 7.0
%%cve:2026-69272%% No No - - Important 7.1 6.2
%%cve:2026-69313%% No No - - Important 7.1 6.2
%%cve:2026-69336%% No No - - Important 7.1 6.2
Microsoft Standard XPS Information Disclosure Vulnerability
%%cve:2026-68881%% No No - - Important 5.5 4.8
%%cve:2026-68891%% No No - - Important 4.7 4.1
%%cve:2026-69308%% No No - - Important 5.5 4.8
%%cve:2026-69345%% No No - - Important 5.5 4.8
%%cve:2026-69367%% No No - - Important 5.5 4.8
%%cve:2026-69376%% No No - - Important 5.5 4.8
Microsoft Standard XPS Remote Code Execution Vulnerability
%%cve:2026-69824%% No No - - Important 9.8 8.5
Microsoft Storage Port Driver Elevation of Privilege Vulnerability
%%cve:2026-72946%% No No - - Important 7.8 6.8
Microsoft Teams for Android Information Disclosure Vulnerability
%%cve:2026-65812%% No No - - Important 6.8 5.9
%%cve:2026-69559%% No No - - Important 5.8 5.1
Microsoft Trace Data Helper Elevation of Privilege Vulnerability
%%cve:2026-56198%% No No - - Important 7.8 6.8
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability
%%cve:2026-69276%% No No - - Important 9.8 8.5
Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability
%%cve:2026-69420%% No No - - Important 7.8 6.8
%%cve:2026-69427%% No No - - Important 8.0 7.0
Microsoft WDAC OLE DB provider for SQL Remote Code Execution Vulnerability
%%cve:2026-72933%% No No - - Important 8.8 7.7
Microsoft WebP Image Extension Remote Code Execution Vulnerability
%%cve:2026-70351%% No No - - Critical 8.8 7.7
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
%%cve:2026-62706%% No No - - Important 8.8 7.7
%%cve:2026-62744%% No No - - Important 8.8 7.7
%%cve:2026-69386%% No No - - Important 8.8 7.7
%%cve:2026-69408%% No No - - Important 9.8 8.5
%%cve:2026-69511%% No No - - Important 8.8 7.7
%%cve:2026-69601%% No No - - Critical 8.8 7.7
Microsoft Windows PDF Remote Code Execution Vulnerability
%%cve:2026-69586%% No No - - Important 9.8 8.5
Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
%%cve:2026-78451%% No No - - Important 6.8 5.9
Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
%%cve:2026-78452%% No No - - Important 4.6 4.0
%%cve:2026-78453%% No No - - Important 6.5 5.7
Microsoft Windows Search Component Elevation of Privilege Vulnerability
%%cve:2026-68896%% No No - - Important 7.8 6.8
%%cve:2026-69305%% No No - - Important 7.1 6.2
%%cve:2026-69322%% No No - - Important 8.0 7.0
%%cve:2026-69585%% No No - - Important 7.8 6.8
%%cve:2026-69600%% No No - - Important 7.0 6.1
%%cve:2026-69608%% No No - - Important 7.8 6.8
%%cve:2026-69911%% No No - - Important 7.0 6.1
Microsoft Windows Search Component Information Disclosure Vulnerability
%%cve:2026-69507%% No No - - Important 5.7 5.0
%%cve:2026-70145%% No No - - Important 5.5 4.8
Microsoft Windows Search Component Tampering Vulnerability
%%cve:2026-69453%% No No - - Important 5.5 4.8
%%cve:2026-69554%% No No - - Important 5.5 4.8
Microsoft Windows Speech Elevation of Privilege Vulnerability
%%cve:2026-69444%% No No - - Important 7.8 6.8
%%cve:2026-69456%% No No - - Important 7.8 6.8
Microsoft Windows Speech Tampering Vulnerability
%%cve:2026-69531%% No No - - Important 5.5 4.8
Microsoft Word Remote Code Execution Vulnerability
%%cve:2026-62804%% No No - - Important 7.8 6.8
%%cve:2026-78510%% No No - - Critical 9.8 8.5
%%cve:2026-81952%% No No - - Critical 8.8 7.7
Power Automate Elevation of Privilege Vulnerability
(no customer action required)
%%cve:2026-65818%% No No - - Critical 8.5 7.4
PowerShell Elevation of Privilege Vulnerability
%%cve:2026-69807%% No No - - Important 8.0 7.0
Push Message Routing Service Information Disclosure Vulnerability
%%cve:2026-69303%% No No - - Important 5.5 4.8
RPC Runtime Library Remote Code Execution Vulnerability
%%cve:2026-69819%% No No - - Important 9.8 8.5
Raw Image Extension Remote Code Execution Vulnerability
%%cve:2026-69649%% No No - - Critical 8.8 7.7
Remote Desktop Client Remote Code Execution Vulnerability
%%cve:2026-68828%% No No - - Important 8.8 7.7
%%cve:2026-69358%% No No - - Important 7.1 6.2
%%cve:2026-69485%% No No - - Important 8.8 7.7
%%cve:2026-78463%% No No - - Important 8.8 7.7
%%cve:2026-80074%% No No - - Important 8.8 7.7
%%cve:2026-80077%% No No - - Important 8.8 7.7
%%cve:2026-83998%% No No - - Important 8.8 7.7
Remote Desktop Gateway Service Elevation of Privilege Vulnerability
%%cve:2026-69292%% No No - - Important 7.0 6.1
%%cve:2026-69338%% No No - - Important 7.1 6.2
Remote Desktop Licensing Service Elevation of Privilege Vulnerability
%%cve:2026-68893%% No No - - Important 7.1 6.2
Remote Desktop ServicesRemote Code Execution Vulnerability
%%cve:2026-69514%% No No - - Important 7.5 6.5
%%cve:2026-69525%% No No - - Important 9.8 8.5
%%cve:2026-69536%% No No - - Important 7.1 6.2
%%cve:2026-69539%% No No - - Important 7.5 6.5
%%cve:2026-69599%% No No - - Important 7.5 6.5
Role: Windows Fax Service Elevation of Privilege Vulnerability
%%cve:2026-69509%% No No - - Important 7.8 6.8
%%cve:2026-69621%% No No - - Important 7.0 6.1
%%cve:2026-72944%% No No - - Important 7.8 6.8
SQL Server Elevation of Privilege Vulnerability
%%cve:2026-66820%% No No - - Important 8.8 7.7
%%cve:2026-73028%% No No - - Important 8.8 7.7
%%cve:2026-77480%% No No - - Important 8.8 7.7
%%cve:2026-77483%% No No - - Important 8.8 7.7
%%cve:2026-77485%% No No - - Important 7.0 6.1
%%cve:2026-77487%% No No - - Important 8.8 7.7
SQL Server Remote Code Execution Vulnerability
%%cve:2026-78456%% No No - - Important 8.8 7.7
Skype for Business Information Disclosure Vulnerability
%%cve:2026-66304%% No No - - Important 7.5 6.5
%%cve:2026-66306%% No No - - Important 6.5 5.7
Skype for Business Remote Code Execution Vulnerability
%%cve:2026-66302%% No No - - Critical 9.8 8.5
Skype for Business Spoofing Vulnerability
%%cve:2026-63523%% No No - - Important 6.5 5.7
%%cve:2026-66305%% No No - - Important 7.1 6.2
%%cve:2026-69642%% No No - - Important 6.5 5.7
%%cve:2026-69646%% No No - - Important 8.3 7.2
Skype for Business and Lync Denial of Service Vulnerability
%%cve:2026-66303%% No No - - Important 6.5 5.7
%%cve:2026-66307%% No No - - Important 7.5 6.5
%%cve:2026-66308%% No No - - Important 6.5 5.7
Spring Cloud Azure Elevation of Privilege Vulnerability
%%cve:2026-69854%% No No - - Critical 9.0 7.8
Storage Spaces Controller Information Disclosure Vulnerability
%%cve:2026-69568%% No No - - Important 5.5 4.8
Telnet Client Remote Code Execution Vulnerability
%%cve:2026-69431%% No No - - Important 9.8 8.5
Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability
%%cve:2026-69384%% No No - - Important 7.1 6.2
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
%%cve:2026-69541%% No No - - Important 7.8 6.8
%%cve:2026-69549%% No No - - Important 7.0 6.1
%%cve:2026-69611%% No No - - Important 7.0 6.1
%%cve:2026-69681%% No No - - Important 8.0 7.0
%%cve:2026-70574%% No No - - Important 7.8 6.8
Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability
%%cve:2026-81355%% No No - - Critical 7.5 6.5
Visual Studio Code Information Disclosure Vulnerability
%%cve:2026-81383%% No No - - Important 7.4 6.4
Visual Studio Code Security Feature Bypass Vulnerability
%%cve:2026-70334%% No No - - Important 7.8 6.8
%%cve:2026-78461%% No No - - Important 7.4 6.4
%%cve:2026-78462%% No No - - Important 8.8 7.7
%%cve:2026-81356%% No No - - Important 8.2 7.1
%%cve:2026-81357%% No No - - Important 8.2 7.1
%%cve:2026-81376%% No No - - Important 9.6 8.3
%%cve:2026-81378%% No No - - Important 8.2 7.1
%%cve:2026-81379%% No No - - Important 8.2 7.1
Visual Studio Code Tampering Vulnerability
%%cve:2026-81377%% No No - - Important 6.5 5.7
Visual Studio Remote Code Execution Vulnerability
%%cve:2026-77906%% No No - - Important 8.8 7.7
%%cve:2026-77907%% No No - - Important 8.8 7.7
Volume Manager Driver Elevation of Privilege Vulnerability
%%cve:2026-69407%% No No - - Important 7.8 6.8
%%cve:2026-69418%% No No - - Important 8.0 7.0
%%cve:2026-69432%% No No - - Important 7.8 6.8
Volume Shadow Copy Elevation of Privilege Vulnerability
%%cve:2026-72985%% No No - - Important 6.8 5.9
Web Media Extensions Remote Code Execution Vulnerability
%%cve:2026-81352%% No No - - Critical 8.8 7.7
Win32k Information Disclosure Vulnerability
%%cve:2026-69609%% No No - - Important 5.5 4.8
%%cve:2026-69808%% No No - - Important 5.5 4.8
%%cve:2026-69832%% No No - - Important 5.6 4.9
%%cve:2026-69853%% No No - - Important 4.7 4.1
%%cve:2026-70290%% No No - - Important 5.5 4.8
Windows AF_UNIX Socket Provider Elevation of Privilege Vulnerability
%%cve:2026-70565%% No No - - Important 7.0 6.1
Windows ALPC Elevation of Privilege Vulnerability
%%cve:2026-69834%% No No - - Important 7.0 6.1
%%cve:2026-69874%% No No - - Critical 8.2 7.1
Windows Accounts Control Elevation of Privilege Vulnerability
%%cve:2026-69654%% No No - - Important 7.0 6.1
%%cve:2026-69816%% No No - - Important 7.0 6.1
Windows Active Directory Domain Services Denial of Service Vulnerability
%%cve:2026-62762%% No No - - Important 6.5 5.7
%%cve:2026-69809%% No No - - Important 7.5 6.5
Windows Active Directory Domain Services Remote Code Execution Vulnerability
%%cve:2026-62813%% No No - - Important 7.5 6.5
%%cve:2026-69524%% No No - - Important 8.1 7.1
%%cve:2026-69546%% No No - - Important 8.1 7.1
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
%%cve:2026-85880%% No Yes - - Important 7.8 6.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
%%cve:2026-50349%% No No - - Important 7.0 6.1
%%cve:2026-70342%% No No - - Important 8.1 7.1
Windows Audio Service Elevation of Privilege Vulnerability
%%cve:2026-69311%% No No - - Important 7.0 6.1
%%cve:2026-69394%% No No - - Important 7.0 6.1
%%cve:2026-69447%% No No - - Important 7.8 6.8
%%cve:2026-69540%% No No - - Important 7.0 6.1
%%cve:2026-69604%% No No - - Important 7.8 6.8
%%cve:2026-69692%% No No - - Important 7.0 6.1
%%cve:2026-69801%% No No - - Important 7.8 6.8
%%cve:2026-70562%% No No - - Important 7.0 6.1
Windows Authentication Methods Elevation of Privilege Vulnerability
%%cve:2026-73005%% No No - - Important 7.0 6.1
Windows Autopilot Tampering Vulnerability
%%cve:2026-73004%% No No - - Important 5.5 4.8
Windows Bind Filter Driver Elevation of Privilege Vulnerability
%%cve:2026-68825%% No No - - Important 7.0 6.1
Windows Biometric Service Elevation of Privilege Vulnerability
%%cve:2026-69293%% No No - - Important 7.8 6.8
%%cve:2026-69298%% No No - - Important 7.8 6.8
%%cve:2026-69323%% No No - - Important 7.8 6.8
%%cve:2026-69352%% No No - - Important 7.8 6.8
%%cve:2026-69476%% No No - - Important 7.8 6.8
%%cve:2026-69489%% No No - - Important 7.8 6.8
%%cve:2026-69580%% No No - - Important 7.8 6.8
%%cve:2026-69583%% No No - - Important 7.8 6.8
%%cve:2026-69589%% No No - - Important 7.8 6.8
%%cve:2026-69593%% No No - - Important 7.8 6.8
%%cve:2026-69727%% No No - - Important 8.0 7.0
%%cve:2026-69738%% No No - - Important 7.8 6.8
%%cve:2026-69773%% No No - - Important 8.0 7.0
%%cve:2026-69787%% No No - - Important 7.8 6.8
%%cve:2026-69826%% No No - - Important 8.0 7.0
%%cve:2026-70572%% No No - - Important 7.8 6.8
%%cve:2026-70573%% No No - - Important 7.0 6.1
%%cve:2026-70581%% No No - - Important 7.8 6.8
%%cve:2026-72941%% No No - - Important 7.8 6.8
%%cve:2026-72988%% No No - - Important 7.8 6.8
%%cve:2026-72990%% No No - - Important 7.8 6.8
%%cve:2026-72991%% No No - - Important 7.8 6.8
%%cve:2026-72992%% No No - - Important 7.8 6.8
%%cve:2026-72993%% No No - - Important 7.8 6.8
%%cve:2026-72994%% No No - - Important 7.8 6.8
%%cve:2026-72995%% No No - - Important 7.8 6.8
%%cve:2026-72996%% No No - - Important 7.8 6.8
%%cve:2026-72997%% No No - - Important 7.8 6.8
%%cve:2026-73000%% No No - - Important 7.8 6.8
%%cve:2026-73001%% No No - - Important 7.8 6.8
%%cve:2026-73002%% No No - - Important 7.8 6.8
%%cve:2026-73007%% No No - - Important 7.8 6.8
%%cve:2026-73011%% No No - - Important 7.8 6.8
%%cve:2026-73015%% No No - - Important 7.8 6.8
%%cve:2026-73020%% No No - - Important 7.8 6.8
%%cve:2026-73021%% No No - - Important 7.8 6.8
%%cve:2026-73026%% No No - - Important 7.8 6.8
%%cve:2026-77489%% No No - - Important 7.8 6.8
%%cve:2026-78447%% No No - - Important 7.8 6.8
%%cve:2026-78448%% No No - - Important 7.8 6.8
%%cve:2026-83954%% No No - - Important 7.8 6.8
%%cve:2026-83955%% No No - - Important 7.8 6.8
%%cve:2026-83967%% No No - - Important 7.8 6.8
%%cve:2026-83968%% No No - - Important 7.8 6.8
%%cve:2026-83969%% No No - - Important 7.8 6.8
%%cve:2026-83970%% No No - - Important 7.8 6.8
%%cve:2026-83971%% No No - - Important 7.8 6.8
%%cve:2026-83972%% No No - - Important 7.8 6.8
%%cve:2026-83973%% No No - - Important 7.8 6.8
%%cve:2026-83974%% No No - - Important 7.8 6.8
%%cve:2026-83975%% No No - - Important 7.8 6.8
%%cve:2026-83976%% No No - - Important 7.8 6.8
%%cve:2026-83977%% No No - - Important 7.8 6.8
%%cve:2026-83978%% No No - - Important 7.8 6.8
%%cve:2026-83979%% No No - - Important 7.8 6.8
%%cve:2026-83980%% No No - - Important 7.8 6.8
%%cve:2026-83981%% No No - - Important 7.8 6.8
%%cve:2026-83982%% No No - - Important 7.8 6.8
%%cve:2026-83983%% No No - - Important 7.8 6.8
%%cve:2026-83985%% No No - - Important 7.8 6.8
%%cve:2026-83986%% No No - - Important 7.8 6.8
%%cve:2026-83987%% No No - - Important 7.8 6.8
%%cve:2026-83988%% No No - - Important 7.8 6.8
Windows Biometric Service Information Disclosure Vulnerability
%%cve:2026-73008%% No No - - Important 5.5 4.8
Windows BitLocker Elevation of Privilege Vulnerability
%%cve:2026-69458%% No No - - Important 8.0 7.0
Windows BitLocker Remote Code Execution Vulnerability
%%cve:2026-69449%% No No - - Important 6.7 5.8
Windows Bluetooth Port Driver Elevation of Privilege Vulnerability
%%cve:2026-69817%% No No - - Important 7.0 6.1
Windows Bluetooth Port Driver Information Disclosure Vulnerability
%%cve:2026-68849%% No No - - Important 4.7 4.1
Windows Bluetooth Service Elevation of Privilege Vulnerability
%%cve:2026-69388%% No No - - Important 7.0 6.1
%%cve:2026-69398%% No No - - Important 7.0 6.1
%%cve:2026-69448%% No No - - Important 7.0 6.1
%%cve:2026-69889%% No No - - Important 7.0 6.1
Windows Boot Manager Elevation of Privilege Vulnerability
%%cve:2026-77892%% No No - - Important 6.8 5.9
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
%%cve:2026-69735%% No No - - Important 7.0 6.1
Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
%%cve:2026-69391%% No No - - Important 7.8 6.8
Windows CD-ROM Driver Elevation of Privilege Vulnerability
%%cve:2026-69283%% No No - - Important 7.8 6.8
%%cve:2026-69561%% No No - - Important 7.8 6.8
Windows CD-ROM Driver Information Disclosure Vulnerability
%%cve:2026-78454%% No No - - Important 5.5 4.8
%%cve:2026-78508%% No No - - Important 4.6 4.0
Windows Camera Frame Server Monitor Elevation of Privilege Vulnerability
%%cve:2026-69542%% No No - - Important 7.8 6.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
%%cve:2026-69279%% No No - - Important 7.0 6.1
%%cve:2026-80093%% No No - - Important 7.0 6.1
Windows Cloud Files Mini Filter Driver Tampering Vulnerability
%%cve:2026-83991%% No No - - Important 5.5 4.8
Windows Compressed Folder Elevation of Privilege Vulnerability
%%cve:2026-69445%% No No - - Important 7.8 6.8
Windows Compressed Folder Information Disclosure Vulnerability
%%cve:2026-70019%% No No - - Important 6.5 5.7
Windows Compressed Folder Remote Code Execution Vulnerability
%%cve:2026-69496%% No No - - Important 9.8 8.5
Windows Connected User Experiences and Telemetry Information Disclosure Vulnerability
%%cve:2026-69267%% No No - - Important 6.5 5.7
Windows Container Manager Service Security Feature Bypass Vulnerability
%%cve:2026-69771%% No No - - Important 4.7 4.1
Windows Core Messaging Elevation of Privilege Vulnerability
%%cve:2026-70583%% No No - - Important 7.8 6.8
%%cve:2026-70584%% No No - - Important 7.8 6.8
Windows Credential Guard Elevation of Privilege Vulnerability
%%cve:2026-70578%% No No - - Important 7.0 6.1
%%cve:2026-72958%% No No - - Critical 8.2 7.1
Windows Credential Providers Elevation of Privilege Vulnerability
%%cve:2026-69790%% No No - - Important 7.8 6.8
%%cve:2026-69814%% No No - - Important 7.0 6.1
Windows Credential Providers Remote Code Execution Vulnerability
%%cve:2026-69729%% No No - - Important 8.8 7.7
Windows DCOM Server Elevation of Privilege Vulnerability
%%cve:2026-69284%% No No - - Important 7.8 6.8
Windows DHCP Client Denial of Service Vulnerability
%%cve:2026-69781%% No No - - Important 6.5 5.7
Windows DHCP Client Elevation of Privilege Vulnerability
%%cve:2026-69777%% No No - - Important 8.0 7.0
Windows DHCP Server Denial of Service Vulnerability
%%cve:2026-69342%% No No - - Important 7.5 6.5
%%cve:2026-69405%% No No - - Important 5.7 5.0
%%cve:2026-69416%% No No - - Important 5.7 5.0
%%cve:2026-69497%% No No - - Important 6.5 5.7
%%cve:2026-69637%% No No - - Important 5.7 5.0
%%cve:2026-69679%% No No - - Important 5.7 5.0
%%cve:2026-70065%% No No - - Important 7.5 6.5
%%cve:2026-77494%% No No - - Important 7.5 6.5
%%cve:2026-77498%% No No - - Important 7.5 6.5
%%cve:2026-77499%% No No - - Important 7.5 6.5
%%cve:2026-77501%% No No - - Important 7.5 6.5
%%cve:2026-77502%% No No - - Important 7.5 6.5
%%cve:2026-77886%% No No - - Important 7.5 6.5
%%cve:2026-77888%% No No - - Important 7.5 6.5
%%cve:2026-77889%% No No - - Important 7.5 6.5
%%cve:2026-77890%% No No - - Important 7.5 6.5
%%cve:2026-77893%% No No - - Important 7.5 6.5
%%cve:2026-77895%% No No - - Important 7.5 6.5
Windows DHCP Server Elevation of Privilege Vulnerability
%%cve:2026-69415%% No No - - Important 6.8 5.9
Windows DHCP Server Information Disclosure Vulnerability
%%cve:2026-69297%% No No - - Important 6.5 5.7
%%cve:2026-69803%% No No - - Important 5.9 5.2
%%cve:2026-69929%% No No - - Important 5.9 5.2
%%cve:2026-69930%% No No - - Important 5.9 5.2
%%cve:2026-70124%% No No - - Important 5.9 5.2
Windows DHCP Server Remote Code Execution Vulnerability
%%cve:2026-69266%% No No - - Important 8.8 7.7
%%cve:2026-69412%% No No - - Important 8.0 7.0
%%cve:2026-69510%% No No - - Important 8.1 7.1
%%cve:2026-69547%% No No - - Important 8.8 7.7
%%cve:2026-69620%% No No - - Important 8.1 7.1
%%cve:2026-69845%% No No - - Critical 9.8 8.5
%%cve:2026-69847%% No No - - Important 8.0 7.0
%%cve:2026-69876%% No No - - Important 8.0 7.0
%%cve:2026-69878%% No No - - Important 6.4 5.6
%%cve:2026-72979%% No No - - Critical 9.8 8.5
%%cve:2026-77887%% No No - - Important 6.4 5.6
%%cve:2026-77891%% No No - - Important 6.4 5.6
Windows DNS Denial of Service Vulnerability
%%cve:2026-69631%% No No - - Important 7.5 6.5
%%cve:2026-70091%% No No - - Important 5.9 5.2
Windows DNS Elevation of Privilege Vulnerability
%%cve:2026-69310%% No No - - Important 7.0 6.1
%%cve:2026-72948%% No No - - Important 6.7 5.8
Windows DNS Information Disclosure Vulnerability
%%cve:2026-69369%% No No - - Important 5.5 4.8
%%cve:2026-69672%% No No - - Important 5.5 4.8
Windows DNS Remote Code Execution Vulnerability
%%cve:2026-72987%% No No - - Critical 8.1 7.1
Windows DNS Server Denial of Service Vulnerability
%%cve:2026-78523%% No No - - Important 5.9 5.2
Windows DNS Server Remote Code Execution Vulnerability
%%cve:2026-69551%% No No - - Important 8.8 7.7
%%cve:2026-69730%% No No - - Critical 9.8 8.5
%%cve:2026-69782%% No No - - Important 8.1 7.1
%%cve:2026-69813%% No No - - Critical 8.1 7.1
%%cve:2026-69827%% No No - - Critical 8.1 7.1
%%cve:2026-69858%% No No - - Critical 8.1 7.1
%%cve:2026-69989%% No No - - Important 8.1 7.1
%%cve:2026-72928%% No No - - Important 7.5 6.5
%%cve:2026-77505%% No No - - Critical 8.1 7.1
Windows DNS Spoofing Vulnerability
%%cve:2026-69680%% No No - - Important 8.1 7.1
Windows DWM Core Library Elevation of Privilege Vulnerability
%%cve:2026-69775%% No No - - Important 7.1 6.2
Windows Defender Firewall Service Elevation of Privilege Vulnerability
%%cve:2026-70568%% No No - - Important 7.0 6.1
Windows Defender Firewall Service Information Disclosure Vulnerability
%%cve:2026-68831%% No No - - Important 5.5 4.8
Windows Deployment Services Remote Code Execution Vulnerability
%%cve:2026-69607%% No No - - Important 7.5 6.5
%%cve:2026-72943%% No No - - Important 7.5 6.5
%%cve:2026-72954%% No No - - Critical 7.5 6.5
%%cve:2026-72957%% No No - - Critical 7.8 6.8
Windows Device Association Broker Service Elevation of Privilege Vulnerability
%%cve:2026-69314%% No No - - Important 7.1 6.2
%%cve:2026-69693%% No No - - Important 7.0 6.1
Windows Device Association Service Elevation of Privilege Vulnerability
%%cve:2026-69296%% No No - - Important 7.1 6.2
%%cve:2026-69478%% No No - - Important 7.8 6.8
%%cve:2026-69488%% No No - - Important 7.0 6.1
%%cve:2026-69574%% No No - - Important 7.0 6.1
%%cve:2026-69581%% No No - - Important 7.0 6.1
%%cve:2026-69711%% No No - - Important 7.0 6.1
%%cve:2026-69714%% No No - - Important 8.0 7.0
%%cve:2026-69791%% No No - - Important 7.0 6.1
%%cve:2026-69866%% No No - - Important 7.0 6.1
%%cve:2026-77500%% No No - - Important 7.8 6.8
%%cve:2026-83940%% No No - - Important 7.0 6.1
Windows Device Health Attestation (DHA) Information Disclosure Vulnerability
%%cve:2026-69443%% No No - - Important 7.5 7.5
Windows Devices Human Interface Elevation of Privilege Vulnerability
%%cve:2026-69472%% No No - - Important 7.0 6.1
Windows Direct Show Remote Code Execution Vulnerability
%%cve:2026-69715%% No No - - Important 9.8 8.5
Windows Display Enhancement Service Elevation of Privilege Vulnerability
%%cve:2026-70567%% No No - - Important 7.0 6.1
Windows Distributed File System (DFS) Denial of Service Vulnerability
%%cve:2026-78446%% No No - - Important 5.3 4.6
Windows Distributed File System (DFS) Elevation of Privilege Vulnerability
%%cve:2026-69424%% No No - - Important 7.8 6.8
Windows Embedded Mode Service Elevation of Privilege Vulnerability
%%cve:2026-69430%% No No - - Important 7.0 6.1
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
%%cve:2026-69688%% No No - - Important 7.1 6.2
%%cve:2026-69841%% No No - - Important 7.8 6.8
Windows Encrypting File System (EFS) Information Disclosure Vulnerability
%%cve:2026-69794%% No No - - Important 5.5 4.8
Windows Enterprise App Management Elevation of Privilege Vulnerability
%%cve:2026-69481%% No No - - Important 8.0 7.0
%%cve:2026-69907%% No No - - Important 7.8 6.8
Windows Error Reporting Elevation of Privilege Vulnerability
%%cve:2026-68894%% No No - - Important 8.0 7.0
%%cve:2026-69362%% No No - - Important 7.0 6.1
%%cve:2026-69433%% No No - - Important 7.8 6.8
%%cve:2026-69436%% No No - - Important 7.8 6.8
%%cve:2026-69450%% No No - - Important 7.8 6.8
%%cve:2026-69462%% No No - - Important 8.0 7.0
%%cve:2026-69513%% No No - - Important 7.8 6.8
%%cve:2026-69612%% No No - - Important 7.8 6.8
%%cve:2026-69896%% No No - - Important 7.0 6.1
%%cve:2026-83996%% No No - - Important 8.8 7.7
Windows Error Reporting Information Disclosure Vulnerability
%%cve:2026-69684%% No No - - Important 5.5 4.8
Windows Error Reporting Tampering Vulnerability
%%cve:2026-69482%% No No - - Important 7.1 6.2
Windows Event Logging Service Remote Code Execution Vulnerability
%%cve:2026-69493%% No No - - Important 9.8 8.5
%%cve:2026-69494%% No No - - Important 8.8 7.7
%%cve:2026-69495%% No No - - Important 8.8 7.7
Windows Failover Cluster Elevation of Privilege Vulnerability
%%cve:2026-71338%% No No - - Important 6.4 5.6
Windows Failover Cluster Information Disclosure Vulnerability
%%cve:2026-72989%% No No - - Important 7.5 6.5
Windows Fast FAT Driver Elevation of Privilege Vulnerability
%%cve:2026-68878%% No No - - Important 8.0 7.0
Windows Fast FAT Driver Remote Code Execution Vulnerability
%%cve:2026-69347%% No No - - Important 7.4 6.4
Windows File History Service Elevation of Privilege Vulnerability
%%cve:2026-68837%% No No - - Important 7.0 6.1
%%cve:2026-71340%% No No - - Important 7.0 6.1
%%cve:2026-72947%% No No - - Important 6.4 5.6
Windows GDI Information Disclosure Vulnerability
%%cve:2026-77491%% No No - - Important 5.5 4.8
Windows GDI+ Elevation of Privilege Vulnerability
%%cve:2026-68827%% No No - - Important 8.0 7.0
Windows GDI+ Information Disclosure Vulnerability
%%cve:2026-69288%% No No - - Important 5.5 4.8
Windows Graphics Component Remote Code Execution Vulnerability
%%cve:2026-77493%% No No - - Critical 9.8 8.5
%%cve:2026-81955%% No No - - Critical 8.8 7.7
Windows Group Policy Elevation of Privilege Vulnerability
%%cve:2026-69717%% No No - - Important 8.0 7.0
Windows HTTP Print Provider Remote Code Execution Vulnerability
%%cve:2026-69623%% No No - - Important 8.0 7.0
%%cve:2026-69769%% No No - - Critical 9.8 8.5
Windows HTTP.sys Elevation of Privilege Vulnerability
%%cve:2026-69597%% No No - - Important 7.1 6.2
Windows Hello Elevation of Privilege Vulnerability
%%cve:2026-69710%% No No - - Critical 7.5 6.5
%%cve:2026-69725%% No No - - Critical 7.8 6.8
%%cve:2026-69740%% No No - - Critical 8.8 7.7
%%cve:2026-69784%% No No - - Critical 8.8 7.7
%%cve:2026-69799%% No No - - Critical 7.8 6.8
%%cve:2026-69820%% No No - - Critical 8.2 7.1
%%cve:2026-69864%% No No - - Critical 7.8 6.8
%%cve:2026-81354%% No No - - Critical 8.2 7.1
Windows Hello Security Feature Bypass Vulnerability
%%cve:2026-72980%% No No - - Critical 4.4 3.9
Windows Host Guardian Service Elevation of Privilege Vulnerability
%%cve:2026-69682%% No No - - Important 7.0 6.1
Windows Hyper-V Elevation of Privilege Vulnerability
%%cve:2026-69553%% No No - - Important 7.1 6.2
%%cve:2026-72961%% No No - - Critical 8.2 7.1
Windows Hyper-V Remote Code Execution Vulnerability
%%cve:2026-69603%% No No - - Critical 8.8 7.7
%%cve:2026-69910%% No No - - Important 9.8 8.5
%%cve:2026-80083%% No No - - Critical 8.8 7.7
Windows IP Address Management (IPAM) Service Elevation of Privilege Vulnerability
%%cve:2026-69694%% No No - - Important 7.0 6.1
Windows Image Acquisition Elevation of Privilege Vulnerability
%%cve:2026-69341%% No No - - Important 7.0 6.1
%%cve:2026-69500%% No No - - Important 7.0 6.1
%%cve:2026-69613%% No No - - Important 7.0 6.1
Windows Image Acquisition Information Disclosure Vulnerability
%%cve:2026-69483%% No No - - Important 4.7 4.1
Windows Imaging Component Information Disclosure Vulnerability
%%cve:2026-69318%% No No - - Important 5.5 4.8
Windows Imaging Component Remote Code Execution Vulnerability
%%cve:2026-69499%% No No - - Critical 8.8 7.7
%%cve:2026-69860%% No No - - Critical 8.8 7.7
%%cve:2026-70296%% No No - - Critical 9.8 8.5
%%cve:2026-73013%% No No - - Critical 8.8 7.7
%%cve:2026-73023%% No No - - Critical 8.8 7.7
%%cve:2026-77495%% No No - - Critical 8.8 7.7
%%cve:2026-83992%% No No - - Important 8.8 7.7
Windows Installer Elevation of Privilege Vulnerability
%%cve:2026-62694%% No No - - Important 7.0 6.1
%%cve:2026-69441%% No No - - Important 7.0 6.1
%%cve:2026-71339%% No No - - Important 6.7 5.8
%%cve:2026-72929%% No No - - Important 7.8 6.8
%%cve:2026-77894%% No No - - Important 7.0 6.1
Windows Internet Connection Sharing (ICS) Elevation of Privilege Vulnerability
%%cve:2026-72926%% No No - - Important 7.0 6.1
Windows Internet Connection Sharing (ICS) Tampering Vulnerability
%%cve:2026-72964%% No No - - Important 5.5 4.8
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
%%cve:2026-69587%% No No - - Important 7.5 6.5
%%cve:2026-69881%% No No - - Important 7.5 6.5
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
%%cve:2026-69429%% No No - - Important 7.5 6.5
Windows Kerberos Denial of Service Vulnerability
%%cve:2026-69744%% No No - - Important 7.5 6.5
%%cve:2026-69760%% No No - - Important 7.5 6.5
Windows Kerberos Elevation of Privilege Vulnerability
%%cve:2026-69685%% No No - - Important 7.8 6.8
%%cve:2026-69822%% No No - - Important 7.8 6.8
Windows Kerberos Remote Code Execution Vulnerability
%%cve:2026-69676%% No No - - Critical 8.8 7.7
Windows Kernel Elevation of Privilege Vulnerability
%%cve:2026-68846%% No No - - Important 7.1 6.2
%%cve:2026-68884%% No No - - Important 7.0 6.1
%%cve:2026-69366%% No No - - Important 7.1 6.2
%%cve:2026-69466%% No No - - Important 7.0 6.1
%%cve:2026-69473%% No No - - Important 7.0 6.1
%%cve:2026-69578%% No No - - Important 7.0 6.1
%%cve:2026-83942%% No No - - Important 7.8 6.8
%%cve:2026-85360%% No No - - Important 7.0 6.1
Windows Kernel Information Disclosure Vulnerability
%%cve:2026-69406%% No No - - Important 5.5 4.8
%%cve:2026-69723%% No No - - Important 5.7 5.0
Windows Kernel Remote Code Execution Vulnerability
%%cve:2026-69669%% No No - - Important 8.8 7.7
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
%%cve:2026-69421%% No No - - Important 7.8 6.8
Windows Key Distribution Center Denial of Service Vulnerability
%%cve:2026-84001%% No No - - Important 7.5 6.5
Windows Key Distribution Center Remote Code Execution Vulnerability
%%cve:2026-69712%% No No - - Critical 8.8 7.7
Windows LDAP - Lightweight Directory Access Protocol Denial of Service Vulnerability
%%cve:2026-69428%% No No - - Important 7.5 6.5
Windows License Manager Elevation of Privilege Vulnerability
%%cve:2026-69281%% No No - - Important 7.0 6.1
Windows License Manager Information Disclosure Vulnerability
%%cve:2026-69315%% No No - - Important 5.5 4.8
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
%%cve:2026-69732%% No No - - Important 8.1 7.1
Windows MIDI Service Module Elevation of Privileges Vulnerability
%%cve:2026-69440%% No No - - Important 7.0 6.1
%%cve:2026-69508%% No No - - Important 7.8 6.8
%%cve:2026-69720%% No No - - Important 7.8 6.8
%%cve:2026-78464%% No No - - Important 7.0 6.1
Windows MIDI Service Module Information Disclosure Vulnerability
%%cve:2026-68842%% No No - - Important 5.5 4.8
%%cve:2026-69339%% No No - - Important 5.5 4.8
Windows Management Instrumentation Elevation of Privilege Vulnerability
%%cve:2026-69451%% No No - - Important 7.1 6.2
%%cve:2026-70582%% No No - - Important 6.4 5.6
%%cve:2026-77905%% No No - - Important 7.0 6.1
Windows Management Instrumentation Information Disclosure Vulnerability
%%cve:2026-69349%% No No - - Important 5.7 5.0
Windows Management Services Elevation of Privilege Vulnerability
%%cve:2026-73012%% No No - - Important 8.8 7.7
Windows Media Elevation of Privilege Vulnerability
%%cve:2026-69891%% No No - - Important 7.0 6.1
Windows Media Player Remote Code Execution Vulnerability
%%cve:2026-70203%% No No - - Critical 8.8 7.7
%%cve:2026-72960%% No No - - Critical 8.8 7.7
Windows Message Queuing Elevation of Privilege Vulnerability
%%cve:2026-69645%% No No - - Important 7.0 6.1
Windows Message Queuing Queue Manager Denial of Service Vulnerability
%%cve:2026-68887%% No No - - Important 7.5 6.5
Windows Message Queuing Queue Manager Information Disclosure Vulnerability
%%cve:2026-72932%% No No - - Important 7.5 6.5
Windows Message Queuing Remote Code Execution Vulnerability
%%cve:2026-69579%% No No - - Critical 9.8 8.5
%%cve:2026-83997%% No No - - Important 8.1 7.1
Windows Mobile Broadband Information Disclosure Vulnerability
%%cve:2026-70579%% No No - - Important 7.5 6.5
Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
%%cve:2026-69377%% No No - - Important 7.8 6.8
%%cve:2026-69460%% No No - - Important 7.1 6.2
%%cve:2026-70577%% No No - - Important 7.0 6.1
%%cve:2026-73003%% No No - - Important 7.0 6.1
%%cve:2026-73022%% No No - - Important 7.0 6.1
Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability
%%cve:2026-69674%% No No - - Important 5.5 4.8
Windows Modern Execution Server Elevation of Privilege Vulnerability
%%cve:2026-72963%% No No - - Important 7.0 6.1
Windows NDIS Elevation of Privilege Vulnerability
%%cve:2026-69357%% No No - - Important 7.1 6.2
%%cve:2026-69396%% No No - - Important 7.1 6.2
Windows NFS Portmapper Elevation of Privilege Vulnerability
%%cve:2026-71334%% No No - - Important 7.8 6.8
Windows NTFS Elevation of Privilege Vulnerability
%%cve:2026-68832%% No No - - Important 7.8 6.8
%%cve:2026-68834%% No No - - Important 8.0 7.0
%%cve:2026-68838%% No No - - Important 8.0 7.0
%%cve:2026-68841%% No No - - Important 7.8 6.8
%%cve:2026-69265%% No No - - Important 7.8 6.8
%%cve:2026-69312%% No No - - Important 7.8 6.8
%%cve:2026-69332%% No No - - Important 8.0 7.0
%%cve:2026-69340%% No No - - Important 7.1 6.2
%%cve:2026-69379%% No No - - Important 7.0 6.1
%%cve:2026-69505%% No No - - Important 8.0 7.0
%%cve:2026-69532%% No No - - Important 7.8 6.8
%%cve:2026-69567%% No No - - Important 7.0 6.1
%%cve:2026-69875%% No No - - Important 8.0 7.0
%%cve:2026-72935%% No No - - Important 6.7 5.8
%%cve:2026-77503%% No No - - Important 8.4 7.3
%%cve:2026-83995%% No No - - Important 7.8 6.8
Windows NTFS Information Disclosure Vulnerability
%%cve:2026-68851%% No No - - Important 5.5 4.8
%%cve:2026-69504%% No No - - Important 5.5 4.8
%%cve:2026-69591%% No No - - Important 5.7 5.0
Windows NTFS Remote Code Execution Vulnerability
%%cve:2026-68833%% No No - - Important 6.8 5.9
%%cve:2026-68875%% No No - - Important 7.8 6.8
%%cve:2026-69461%% No No - - Important 8.8 7.7
%%cve:2026-69463%% No No - - Important 9.8 8.5
%%cve:2026-69479%% No No - - Important 8.4 7.3
%%cve:2026-69566%% No No - - Important 6.8 5.9
%%cve:2026-69638%% No No - - Important 8.4 7.3
%%cve:2026-69709%% No No - - Important 7.8 6.8
%%cve:2026-71329%% No No - - Important 6.8 5.9
Windows NTFS Tampering Vulnerability
%%cve:2026-69425%% No No - - Important 4.7 4.1
Windows Netlogon Remote Code Execution Vulnerability
%%cve:2026-72982%% No No - - Critical 9.8 8.5
Windows Netlogon Spoofing Vulnerability
%%cve:2026-62759%% No No - - Important 7.5 6.5
Windows Network Connection Broker Elevation of Privilege Vulnerability
%%cve:2026-72967%% No No - - Important 7.8 6.8
Windows Network Connection Broker Information Disclosure Vulnerability
%%cve:2026-68886%% No No - - Important 5.5 4.8
Windows Network File System Denial of Service Vulnerability
%%cve:2026-69372%% No No - - Important 5.7 5.0
Windows Network File System Remote Code Execution Vulnerability
%%cve:2026-69772%% No No - - Important 8.8 7.7
Windows Notification Elevation of Privilege Vulnerability
%%cve:2026-69648%% No No - - Important 7.0 6.1
Windows OLE DB Information Disclosure Vulnerability
%%cve:2026-78441%% No No - - Important 6.5 5.7
Windows OLE DB Remote Code Execution Vulnerability
%%cve:2026-78442%% No No - - Important 8.8 7.7
Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability
%%cve:2026-69564%% No No - - Important 7.0 6.1
Windows Overlay Filter Elevation of Privilege Vulnerability
%%cve:2026-69350%% No No - - Important 6.7 5.8
%%cve:2026-69368%% No No - - Important 7.8 6.8
%%cve:2026-69371%% No No - - Important 8.0 7.0
%%cve:2026-69373%% No No - - Important 6.7 5.8
Windows Overlay Filter Information Disclosure Vulnerability
%%cve:2026-69316%% No No - - Important 4.7 4.1
%%cve:2026-69343%% No No - - Important 5.5 4.8
%%cve:2026-69474%% No No - - Important 4.8 4.2
Windows Paint Remote Code Execution Vulnerability
%%cve:2026-70586%% No No - - Critical 8.8 7.7
Windows Partition Management Driver Elevation of Privilege Vulnerability
%%cve:2026-69480%% No No - - Important 7.8 6.8
%%cve:2026-69492%% No No - - Important 7.0 6.1
Windows Partition Management Driver Information Disclosure Vulnerability
%%cve:2026-71341%% No No - - Important 5.5 4.8
Windows Performance Monitor Elevation of Privilege Vulnerability
%%cve:2026-69324%% No No - - Important 7.8 6.8
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
%%cve:2026-69459%% No No - - Important 7.8 6.8
Windows Power Dependency Coordinator Tampering Vulnerability
%%cve:2026-69321%% No No - - Important 5.5 4.8
Windows Print Spooler Components Denial of Service Vulnerability
%%cve:2026-69569%% No No - - Important 5.7 5.0
Windows Print Spooler Components Elevation of Privilege Vulnerability
%%cve:2026-68835%% No No - - Important 7.1 6.2
%%cve:2026-68848%% No No - - Important 7.8 6.8
%%cve:2026-69309%% No No - - Important 7.0 6.1
%%cve:2026-69346%% No No - - Important 8.0 7.0
%%cve:2026-69364%% No No - - Important 7.1 6.2
%%cve:2026-69838%% No No - - Important 7.0 6.1
%%cve:2026-69921%% No No - - Important 7.8 6.8
%%cve:2026-70564%% No No - - Important 7.8 6.8
Windows Print Spooler Components Information Disclosure Vulnerability
%%cve:2026-69344%% No No - - Important 5.5 4.8
%%cve:2026-69552%% No No - - Important 5.7 5.0
Windows Print Spooler Remote Code Execution Vulnerability
%%cve:2026-85877%% No No - - Important 8.8 7.7
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
%%cve:2026-69602%% No No - - Important 7.1 6.2
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
%%cve:2026-68845%% No No - - Important 7.8 6.8
%%cve:2026-68876%% No No - - Important 8.0 7.0
%%cve:2026-69534%% No No - - Important 7.8 6.8
%%cve:2026-69563%% No No - - Important 7.0 6.1
Windows Program Compatibility Assistant Service Information Disclosure Vulnerability
%%cve:2026-68873%% No No - - Important 5.5 4.8
%%cve:2026-68874%% No No - - Important 5.7 5.0
Windows Push Notifications Elevation of Privilege Vulnerability
%%cve:2026-62697%% No No - - Important 7.8 6.8
%%cve:2026-69280%% No No - - Important 7.0 6.1
%%cve:2026-69300%% No No - - Important 7.0 6.1
Windows RNDIS Information Disclosure Vulnerability
%%cve:2026-69548%% No No - - Important 4.6 4.0
Windows RNDIS Remote Code Execution Vulnerability
%%cve:2026-69768%% No No - - Important 9.8 8.5
Windows Registry Elevation of Privilege Vulnerability
%%cve:2026-69337%% No No - - Important 7.1 6.2
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
%%cve:2026-69530%% No No - - Critical 8.1 7.1
%%cve:2026-78449%% No No - - Critical 8.1 7.1
%%cve:2026-78450%% No No - - Critical 8.1 7.1
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
%%cve:2026-69331%% No No - - Important 7.0 6.1
%%cve:2026-69455%% No No - - Important 7.8 6.8
%%cve:2026-71333%% No No - - Important 7.0 6.1
%%cve:2026-71342%% No No - - Important 7.0 6.1
Windows Remote Access Connection Manager Remote Code Execution Vulnerability
%%cve:2026-71343%% No No - - Important 7.8 6.8
%%cve:2026-71352%% No No - - Important 8.8 7.7
Windows Remote Access Connection Manager Tampering Vulnerability
%%cve:2026-72966%% No No - - Important 5.5 4.8
Windows Remote Desktop Client Denial of Service Vulnerability
%%cve:2026-77896%% No No - - Important 6.5 5.7
Windows Remote Desktop Client Information Disclosure Vulnerability
%%cve:2026-69317%% No No - - Important 5.7 5.0
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
%%cve:2026-69627%% No No - - Important 5.5 4.8
Windows Remote Desktop Protocol Information Disclosure Vulnerability
%%cve:2026-70587%% No No - - Important 7.5 6.5
Windows Remote Desktop Remote Code Execution Vulnerability
%%cve:2026-69518%% No No - - Critical 8.8 7.7
Windows Remote Desktop Services Elevation of Privilege Vulnerability
%%cve:2026-69287%% No No - - Important 7.0 6.1
%%cve:2026-69475%% No No - - Important 7.8 6.8
%%cve:2026-80096%% No No - - Important 8.8 7.7
Windows Remote Desktop Services Information Disclosure Vulnerability
%%cve:2026-69616%% No No - - Important 5.5 4.8
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
%%cve:2026-83999%% No No - - Important 7.0 6.1
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
%%cve:2026-69617%% No No - - Important 7.0 6.1
%%cve:2026-83952%% No No - - Important 7.8 6.8
Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability
%%cve:2026-72939%% No No - - Important 6.5 5.7
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
%%cve:2026-71351%% No No - - Important 7.0 6.1
%%cve:2026-71353%% No No - - Important 7.0 6.1
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
%%cve:2026-69590%% No No - - Critical 9.8 8.5
%%cve:2026-69852%% No No - - Critical 7.5 6.5
%%cve:2026-70570%% No No - - Important 7.5 6.5
%%cve:2026-72950%% No No - - Critical 8.8 7.7
%%cve:2026-72959%% No No - - Critical 8.8 7.7
Windows SMB Client Elevation of Privilege Vulnerability
%%cve:2026-69544%% No No - - Important 7.8 6.8
Windows SMB Client Information Disclosure Vulnerability
%%cve:2026-69572%% No No - - Important 5.7 5.0
%%cve:2026-69618%% No No - - Important 5.5 4.8
Windows SMB Client Remote Code Execution Vulnerability
%%cve:2026-72936%% No No - - Important 8.1 7.1
Windows SMB Server Denial of Service Vulnerability
%%cve:2026-69374%% No No - - Important 6.5 5.7
Windows SMB Server Information Disclosure Vulnerability
%%cve:2026-69403%% No No - - Important 5.5 4.8
Windows SMB Server Network Transport Driver (srvnet.sys) Denial of Service Vulnerability
%%cve:2026-72949%% No No - - Important 7.5 6.5
Windows Schannel Denial of Service Vulnerability
%%cve:2026-70575%% No No - - Important 5.3 4.6
Windows Schannel Remote Code Execution Vulnerability
%%cve:2026-72940%% No No - - Important 8.8 7.7
Windows Secure Boot Security Feature Bypass Vulnerability
%%cve:2026-69713%% No No - - Important 4.4 3.9
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
%%cve:2026-69501%% No No - - Critical 7.0 6.1
%%cve:2026-69846%% No No - - Critical 8.2 7.1
%%cve:2026-69906%% No No - - Critical 8.2 7.1
%%cve:2026-83939%% No No - - Critical 8.2 7.1
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
%%cve:2026-72931%% No No - - Important 4.7 4.1
Windows Secure Socket Tunneling Protocol (SSTP) Elevation of Privilege Vulnerability
%%cve:2026-71332%% No No - - Important 7.0 6.1
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
%%cve:2026-72930%% No No - - Important 7.0 6.1
%%cve:2026-73009%% No No - - Critical 9.8 8.5
Windows Security Center Elevation of Privilege Vulnerability
%%cve:2026-77899%% No No - - Important 7.0 6.1
Windows Security Health Service Elevation of Privilege Vulnerability
%%cve:2026-78457%% No No - - Important 7.0 6.1
Windows Server Elevation of Privilege Vulnerability
%%cve:2026-56177%% No No - - Important 7.8 6.8
Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability
%%cve:2026-83989%% No No - - Important 7.5 6.5
Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability
%%cve:2026-73024%% No No - - Important 7.8 6.8
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
%%cve:2026-71330%% No No - - Important 7.5 6.5
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
%%cve:2026-69595%% No No - - Critical 9.8 8.5
%%cve:2026-70585%% No No - - Critical 7.0 6.1
%%cve:2026-78445%% No No - - Critical 9.8 8.5
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
%%cve:2026-69289%% No No - - Important 7.8 6.8
Windows Shell Elevation of Privilege Vulnerability
%%cve:2026-69383%% No No - - Important 7.0 6.1
%%cve:2026-69392%% No No - - Important 7.8 6.8
%%cve:2026-69528%% No No - - Important 7.8 6.8
%%cve:2026-69606%% No No - - Important 7.0 6.1
Windows Shell Remote Code Execution Vulnerability
%%cve:2026-69829%% No No - - Critical 9.8 8.5
Windows Shell Spoofing Vulnerability
%%cve:2026-70563%% No No - - Important 8.1 7.1
Windows Smart Card Elevation of Privilege Vulnerability
%%cve:2026-69785%% No No - - Important 7.8 6.8
Windows Spaceport.sys Elevation of Privilege Vulnerability
%%cve:2026-69512%% No No - - Important 8.0 7.0
%%cve:2026-69535%% No No - - Important 7.8 6.8
%%cve:2026-69643%% No No - - Important 8.0 7.0
%%cve:2026-69691%% No No - - Important 7.8 6.8
%%cve:2026-70569%% No No - - Important 7.8 6.8
Windows Spaceport.sys Information Disclosure Vulnerability
%%cve:2026-69390%% No No - - Important 5.5 4.8
%%cve:2026-69393%% No No - - Important 5.7 5.0
%%cve:2026-69741%% No No - - Important 5.5 4.8
%%cve:2026-69770%% No No - - Important 5.5 4.8
%%cve:2026-69895%% No No - - Important 4.7 4.1
%%cve:2026-72942%% No No - - Important 6.5 5.7
Windows Spaceport.sys Remote Code Execution Vulnerability
%%cve:2026-69538%% No No - - Important 7.8 6.8
%%cve:2026-71345%% No No - - Important 7.8 6.8
%%cve:2026-71348%% No No - - Important 6.8 5.9
%%cve:2026-71349%% No No - - Important 6.8 5.9
%%cve:2026-71350%% No No - - Important 6.8 5.9
%%cve:2026-72952%% No No - - Important 7.0 6.1
Windows Storage Elevation of Privilege Vulnerability
%%cve:2026-69328%% No No - - Important 7.8 6.8
Windows Storage Information Disclosure Vulnerability
%%cve:2026-78516%% No No - - Important 4.3 3.8
Windows Storage Management Provider Elevation of Privilege Vulnerability
%%cve:2026-69389%% No No - - Important 7.8 6.8
%%cve:2026-71337%% No No - - Important 7.8 6.8
Windows Storage Port Driver Information Disclosure Vulnerability
%%cve:2026-69381%% No No - - Important 4.6 4.0
%%cve:2026-72937%% No No - - Important 5.5 4.8
%%cve:2026-77492%% No No - - Important 5.5 4.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
%%cve:2026-69290%% No No - - Important 7.8 6.8
%%cve:2026-69575%% No No - - Important 7.0 6.1
Windows Storage Spaces Controller Remote Code Execution Vulnerability
%%cve:2026-68844%% No No - - Important 7.8 6.8
%%cve:2026-68877%% No No - - Important 7.8 6.8
Windows TCP/IP Denial of Service Vulnerability
%%cve:2026-69588%% No No - - Important 7.5 6.5
Windows TCP/IP Elevation of Privilege Vulnerability
%%cve:2026-69385%% No No - - Important 7.0 6.1
%%cve:2026-69404%% No No - - Important 7.0 6.1
%%cve:2026-69757%% No No - - Important 7.1 6.2
%%cve:2026-69761%% No No - - Important 7.1 6.2
Windows TCP/IP Security Feature Bypass Vulnerability
%%cve:2026-69793%% No No - - Important 7.5 6.5
Windows Task Scheduler Information Disclosure Vulnerability
%%cve:2026-72945%% No No - - Important 5.5 4.8
Windows Text Shaping Information Disclosure Vulnerability
%%cve:2026-69353%% No No - - Important 5.5 4.8
Windows Text Shaping Remote Code Execution Vulnerability
%%cve:2026-69786%% No No - - Important 8.1 7.1
Windows URL Moniker Remote Code Execution Vulnerability
%%cve:2026-69434%% No No - - Important 8.8 7.7
Windows URL Moniker Security Feature Bypass Vulnerability
%%cve:2026-73019%% No No - - Important 4.3 3.8
Windows USB Audio Class Driver Information Disclosure Vulnerability
%%cve:2026-69286%% No No - - Important 5.5 4.8
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
%%cve:2026-69270%% No No - - Important 7.8 6.8
%%cve:2026-69307%% No No - - Important 7.8 6.8
%%cve:2026-69413%% No No - - Important 7.0 6.1
%%cve:2026-69469%% No No - - Important 6.6 5.8
%%cve:2026-69571%% No No - - Important 7.8 6.8
%%cve:2026-69687%% No No - - Important 7.8 6.8
%%cve:2026-69707%% No No - - Important 7.8 6.8
%%cve:2026-69859%% No No - - Important 7.0 6.1
Windows USB Driver Elevation of Privilege Vulnerability
%%cve:2026-68840%% No No - - Important 7.0 6.1
%%cve:2026-69295%% No No - - Important 7.8 6.8
%%cve:2026-69503%% No No - - Important 8.0 7.0
%%cve:2026-72953%% No No - - Important 7.8 6.8
Windows USB Driver Information Disclosure Vulnerability
%%cve:2026-69457%% No No - - Important 5.5 4.8
Windows USB Hub Driver Elevation of Privilege Vulnerability
%%cve:2026-72999%% No No - - Important 6.8 5.9
Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability
%%cve:2026-69490%% No No - - Important 6.8 5.9
Windows USB Mass Storage Class Driver Information Disclosure Vulnerability
%%cve:2026-69527%% No No - - Important 5.5 4.8
Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability
%%cve:2026-68839%% No No - - Important 9.8 8.5
Windows USB Video Driver Elevation of Privilege Vulnerability
%%cve:2026-69319%% No No - - Important 7.0 6.1
%%cve:2026-69422%% No No - - Important 7.0 6.1
%%cve:2026-69423%% No No - - Important 8.0 7.0
%%cve:2026-69584%% No No - - Important 7.8 6.8
%%cve:2026-72962%% No No - - Critical 8.2 7.1
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
%%cve:2026-69573%% No No - - Important 7.0 6.1
%%cve:2026-69592%% No No - - Important 7.8 7.8
%%cve:2026-69758%% No No - - Important 7.8 7.8
Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability
%%cve:2026-68830%% No No - - Important 5.5 4.8
%%cve:2026-69351%% No No - - Important 5.5 4.8
Windows Update Stack Elevation of Privilege Vulnerability
%%cve:2026-81963%% No Yes - - Important 7.8 7.2
Windows VHD miniport driver Elevation of Privilege Vulnerability
%%cve:2026-56172%% No No - - Important 7.8 6.8
Windows VOLSNAP.SYS Remote Code Execution Vulnerability
%%cve:2026-69426%% No No - - Important 7.8 6.8
Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability
%%cve:2026-69890%% No No - - Critical 7.5 6.5
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
%%cve:2026-83498%% No No - - Critical 7.8 6.8
Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
%%cve:2026-83501%% No No - - Critical 5.5 4.8
Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
%%cve:2026-69468%% No No - - Important 7.0 6.1
%%cve:2026-69582%% No No - - Important 7.8 6.8
%%cve:2026-77904%% No No - - Important 7.8 6.8
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
%%cve:2026-69291%% No No - - Important 8.8 7.7
%%cve:2026-69334%% No No - - Important 8.8 7.7
Windows Web Platform Storage Elevation of Privilege Vulnerability
%%cve:2026-69708%% No No - - Important 7.0 6.1
Windows WebClient Service Elevation of Privilege Vulnerability
%%cve:2026-72965%% No No - - Important 7.8 6.8
Windows Win32K Security Feature Bypass Vulnerability
%%cve:2026-69792%% No No - - Important 4.7 4.1
Windows Win32k Elevation of Privilege Vulnerability
%%cve:2026-68880%% No No - - Important 8.0 7.0
%%cve:2026-69274%% No No - - Important 7.1 6.2
%%cve:2026-69301%% No No - - Important 8.0 7.0
%%cve:2026-69333%% No No - - Important 7.0 6.1
%%cve:2026-69335%% No No - - Important 7.0 6.1
%%cve:2026-69348%% No No - - Important 7.8 6.8
%%cve:2026-69410%% No No - - Important 7.0 6.1
%%cve:2026-69498%% No No - - Important 7.0 6.1
%%cve:2026-69610%% No No - - Important 7.0 6.1
%%cve:2026-69630%% No No - - Important 7.0 6.1
%%cve:2026-69652%% No No - - Important 7.0 6.1
%%cve:2026-69689%% No No - - Important 8.0 7.0
%%cve:2026-69706%% No No - - Important 7.1 6.2
%%cve:2026-69762%% No No - - Important 8.0 7.0
%%cve:2026-69779%% No No - - Important 7.0 6.1
%%cve:2026-69818%% No No - - Important 7.0 6.1
%%cve:2026-69844%% No No - - Important 7.8 6.8
%%cve:2026-70283%% No No - - Important 7.0 6.1
%%cve:2026-70289%% No No - - Important 7.8 6.8
Windows Wireless Networking Elevation of Privilege Vulnerability
%%cve:2026-69517%% No No - - Important 7.0 6.1
Windows Wireless Wide Area Network Service Information Disclosure Vulnerability
%%cve:2026-69862%% No No - - Important 5.5 4.8
Windows Work Folder Service Elevation of Privilege Vulnerability
%%cve:2026-69560%% No No - - Important 7.0 6.1
Windows Work Folder Service Remote Code Execution Vulnerability
%%cve:2026-71336%% No No - - Important 8.8 7.7
Windows Work Folders Elevation of Privilege Vulnerability
%%cve:2026-80075%% No No - - Important 7.8 6.8
Windows exFAT File System Elevation of Privilege Vulnerability
%%cve:2026-69619%% No No - - Important 8.0 7.0
Windows iSCSI Denial of Service Vulnerability
%%cve:2026-68898%% No No - - Important 6.5 5.7
Windows iSCSI Remote Code Execution Vulnerability
%%cve:2026-69598%% No No - - Important 8.8 7.7
%%cve:2026-69628%% No No - - Important 8.8 7.7
Windows iSCSI Security Feature Bypass Vulnerability
%%cve:2026-73025%% No No - - Important 9.8 8.5
Windows iSCSI Target Service Denial of Service Vulnerability
%%cve:2026-69839%% No No - - Important 6.5 5.7
Winsock Elevation of Privilege Vulnerability
%%cve:2026-72927%% No No - - Important 6.7 5.8
Xbox Gaming Services Elevation of Privilege Vulnerability
%%cve:2026-58611%% No No - - Important 7.8 6.8
Xbox Information Disclosure Vulnerability
%%cve:2026-78455%% No No - - Important 4.3 3.8

--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

0 Comments

Published: 2026-09-06

Critical MikroTik Vulnerability - Patch Now

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.

The patch will attempt to detect compromise and set the "Flagged" status. 

Details:

https://mikrotik.com/supportsec/september-2026-vulnerability

 

 

--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

0 Comments

Published: 2026-09-04

numbat - AI agent observability

numbat logo

Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots.
Absent agent-aware governance, modern enterprises struggle to prevent, detect, or contain multi-hop autonomous exploits, leaving environments vulnerable to lateral movement, shadow collaboration, and unauthorized data exfiltration.
More succinctly, in light of the recent OpenAI/Hugging Face incident, monitoring clearly lags behind agent capability. The tooling to observe what agents are actually doing, in real time, is not yet standard practice, even at the labs building the agents.
To that end, Perplexity AI’s open source numbat offers excellent observability and visibility to supported desktop, CLI, IDE, and gateway agents through local hooks and plugins, OTLP/HTTP logs, and on-disk session artifacts.[1]

Crafted as a Go binary, numbat works seemlessly on macOS, Linux, or Windows. You can download a static binary or install with Go. Read for all features, requirements, configurations, and options. Getting up and running is nearly instant so I’ll focus exclusively on usage. Note that if you install via Go, the numbat binary is then found under /go/bin.
As a regular user of Anthropic, OpenAI, and Google AI offerings, I expected to learn immediate insights, but I was a bit taken aback by the number agents installed on my system. Initial discovery is as easy as ./numbat agents, my insightful result seen in Figure 1.

numbat agents

Figure 1: numbat agent enumeration

A full breakdown of agents is provided, their available configs, what artifacts are available, if a hook is available, whether or not said hook is wired, and the steps necessary to do so. As you can see I’m already hooked for Claude and Gemini, but I did so as follows:

./numbat hook install --agent claude --emit all  
./numbat hook install --agent gemini --emit all

Agent enumeration is great, but with the hook in, the real value proposition emerges. While hooks start in monitor-only mode, the --emit all function writes events, findings, indicators, and applicable enforcement decisions to ~/.numbat/records.ndjson by default.
As such, detection rules come to bear; they are many, and effective. Refer to the built-in rule catalog for detected behaviors. Detectors are defined categorically, including secrets, exfiltration, integrity, execution, reconnaissance, privilege, lateral movement, impact, source control, tampering, persistence, and sequences. Run numbat rules list for the full listing.
After review of said catalog, I opted to test a specific detector and chose an easy one to stimulate: recon.network_sweep where “a named scanner is given an explicit scan or target-list option and a network range.” Easy enough with a quick prompt via ClaudeCode, as seen in Figure 2.

claude nmap

Figure 2: ClaudeCode nmap scan

Sure, an nmap scan isn’t exactly the most invasive or adversarial act one could imagine but it does qualify as something you’re not likely to want having an agent swarm unleashing on your enterprise unabated. So much so that Mitre ATT&CK tags Network Service Discovery as technique T1046 which, in turn, is conveyed via the recon.network_sweep rule and written as a finding, when triggered, to ~/.numbat/records.ndjson if you’re using default installation.
I’m a big fan of jq to render JSON as human readable: jq . ~/.numbat/records.ndjson
The result is a number of related artifacts written to the records file as seen in Figure 3.

numbat recon rule

Figure 3: numbat recon finding

Logically, there may be behaviors or actions you’d also like to block or prevent. numbat rules can be set to enforce as defined in numbat’s enforcement documentation. Specifically, “to enforce a shipped detection selectively, copy its complete YAML file from the matching release’s shipped catalog into a controlled operator rules directory, keep the same id, set enforce: true, and bump the rule version. Validate the effective catalog, then deploy the same directory with the hook”:

numbat rules check --rules-dir /opt/numbat/rules  
numbat hook install --agent claude --managed --rules-dir /opt/numbat/rules --enforce

Additionally, an investigation may be required, under certain circumstances, should inappropriate or unauthorized activity be detected.
Your IR team will appreciate the investigation packaging inherent to numbat.
Create a case ID, write to an output file, build the case artifacts, including a manifest file with SHA256 hashes for integrity matching, and verify the manifest.

numbat scan --case-id inv-03SEP2026 --emit all --output file --output-file investigations.ndjson
numbat case build inv-03SEP2026 --from investigations.ndjson -o inv-03SEP2026.numbat
numbat case verify inv-03SEP2026.numbat

The result is a folder named for the case ID that includes events.ndjson, findings.ndjson, and the .numbat manifest file. The findings are complete and accurate, and as they pertain to my misbehavorior with nmap, robust in their evidence collection, as seen in Figure 4.

numbat findings

Figure 4: numbat investigation finding (snippet)

All good investigators love their timelines. numbat offers a tidy timeliner, called as simply as numbat timeline --agent claudetimeline is a read-only view that groups events by source_agent, source_type, and session_id where each chronological step retains its evidence reference.

Consider the CLI reference required reading for your immediate use.
Recognize that I’ve not covered a number of excellent additional features including all the Deployment options.
These include local use as well as Live OTLP/HTTP capture (numbat collect) and Async HTTP delivery with no external shipper (numbat ship).
Importantly, there are managed configuration (MDM) opportunities for fleet deployments, including a small guided MDM pilot. The options are many, and the flexibility is welcome.
numbat is a really solid offering from the Perplexity crew, and I thoroughly enjoyed the opportunity to investigate the use cases. I see enterprise utilization and deployment opportunities here for sure.

Cheers…until next time.

Russ McRee | @holisticinfosec | infosec.exchange/@holisticinfosec | LinkedIn.com/in/russmcree

0 Comments

Published: 2026-09-02

Honeypot-Omaha and batch.py [Guest Diary]

[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]

Honeypot-Omaha is a DShied Sensor located at the Internet Storm Center (ISC) that is set up as a decoy for the original target and deployed over the internet. It is a flawed and very vulnerable system that was intentionally designed to attract threat actors with malicious intents. I view it as a massive log aggregator that collects data that an analyst like myself can then analyse, hypothesize, synthesize and then generate a cohesive and coherent report.

DShield Sensor uses a collective of tools to track internet threat actors, one of those packaged tools is called “cowrie”. It emulates port twenty-two and twenty-three, which are secure shell and telnet. Automation is at its rise and almost everything has been or would be automated at some point in time. From botnets to password brute force attacks to credentials scraping and gathering of data, we observe more automated activities.

Tools like hashcat and jack the ripper make credential collection easy. So, cowrie waits and listens on the decoy ports set up for DShield Sensor. It exposes these ports to the public facing internet and relays the data to a centralized station (ISC). Which logs every information about that threat actor and its activities. “DShield.org” and the Internet Storm Center—founded by Dr. Johannes Ullrich in November 2000 out of the precursor site Incidents.org—provide valuable threat intelligence.

When a potential threat actor infiltrates the sensor, cowrie records their activities. Questions begin to arise like methods used to access the system, what vulnerability was exploited, did they succeed or fail at their attempts, what commands were used, where it was used, what was exfiltrated. With this valuable intel an analyst can build a time frame of when the activity started and ended. Answers to most of these questions asked would be revealed as we proceed.

The next question is how do I correlate and gather all these data of interest, types, and structure. There are web logs, firewall logs, cowrie logs with credentials and other valuable information. I tried using tools like zeek for data behaviour correlation, carving, and analysis, rwfilter for metadata carving of specific fields of interest and converting to silk then my favorite tool, tcpdump for parsing network traffic packets. 

All these tools are excellent tools but they are multiple tools that perform specific functions. I needed one tool that could consolidate all my logs of data, filter out the relevant data of interest and use those filtered consolidated data to answer all the questions asked on my internship template. For example, an analyst may want to get more information about a specific internet address, and all the activities engaged by that address. 

An analyst has to have a way to input an internet address or fully qualified domain name (FQDN) and it recursively gathers different data of interest related to that address, by searching and querying different “APIs” application programming interfaces for data.

Then converts the data into a tab separated value format, analyzes, correlates, gathers threat intelligence, common vulnerabilities and exposure (CVE), mitre, exploits, threat score, session id, hash and fingerprints, port numbers, geolocation, internet service and cloud service  providers (ISPs or CSP) and a way to mitigate the threat actors activities.

This tool should be able to implement hashing mechanisms using any of the secure algorithms, for example using a combination of symmetric-asymmetric ciphers, and consolidating relevant data across a given directory into one view. Nothing complicated, just a simple script that synthesizes, consolidates data and brings all that into a focused, comprehensive, cohesive functionality and possibly more. Now you see where I am going with this delima.

All data are important but which ones are  relevant to solving my internship questions. After a long research, I had an “Aha!” moment, you can call it an epiphany or what I call my “eureka” moment. That's where the idea of a “batch” process was formulated. I use my recently gained knowledge and skills of the python programming language to write a script called “batch.py”.

Batch is a script based on the python programming language, I wrote to assist me do most of what I described above. Here is the step by step breakdown of what it does. It is composed of “Four” integrated phases of the analysis processing pipeline. The fidelity of “batch.py” is based on the raw logs it parses. For now the logs must be located in the same directory as batch.py. I use secure copy (scp) to download my logs located on my amazon web services to a local directory on my computer.
 
As a security conscious analyst, persistence security of data should be a priority. This is the start of “batch”, you can either log in as full admin or grant access to guests. To use the batch.py program you start by running a bash script on your local terminal window to generate a master password, I use a mac. It uses the secure hashing algorithm(SHA-256) to generate a master and a guest token.You have to generate a master password first by executing the bash script below. 

Start:
Generating master password or guest passcode.
 

 
Authentication and verification are used to prevent unauthorized access to sensitive data. The principle of least privilege (POLP) is a necessary requirement for accountability, monitoring, and data loss prevention. 

Select an option for the authentication process. 

If option two is chosen and an analyst does not have a guest passcode, a message will be generated notifying the analyst that they need to have a guest passcode for them to access the program. 

Select option 3 to generate a guest passcode and login.

Phase 1

After an analyst authenticates and is verified, the phase one process starts by gathering and feeding relevant data through the analysis pipeline, then converts the .json, .log, .gz, and any other relevant data to a .tsv file format. “TSV” stands for tab separated values.

The gathered intelligence data from querying ip-api.com, cve.org and paloaltonetworks.com are broken down into sections and fields to delineate the processing stages. With the integrated unified analysis pipeline design, batch.py is engineered for efficiency, low latency, and the rapid parsing of large volumes of logs.

Phase 2

Stage: 1
This displays on your screen showing a summary of the top 10 unique internet addresses that made contact with honeypot_omaha. 

Stage: 2
As you can observe on what is displayed on the screen. I only have two cowrie protocols shown. There are more but on this stage I am focusing on just a few of the protocols used by cowrie.

Stage: 3
This displays on your screen the top 10 correlation of usernames to their respective internet address.

Stage: 4
This shows the top 10 correlation of passwords to their respective internet addresses.

Stage: 5
This displays the top 10 talkers with possible threat intelligence, attempts, geolocation, and their respective internet service and cloud providers. Not all top talkers are threat actors or have malicious intents. This requires the know-how and expertise of trained analysts to dissect and discern relevant data from noise.

Stage: 6
As an analyst, a long tail analysis of the data of interest will give you an idea of where to start your analysis. Sometimes threat actors use beaconing and command and control to relay data back and forth. Check for specific time intervals.

Stage: 7
Batch aggregates all the data it has parsed and gives a summary of how many attempts were made by the threat actors to an endpoint.

Phase 3
Generates a summary report and visual pie chart compilation.

Stage: 8
Compilation and summarization of data, using matplotlib to create the pie charts in a png file format and generating text document reports. 

Phase 4
This phase displays an interactive menu an analyst can use to further examine and analyze data. It comprises six numbered menu points. Let's start with the first menu.

Stage: 9
An easy navigation menu for an analyst to access detailed information on a given threat actor's internet address and activities.

Menu 1
Any artifacts found or indication of compromise will be displayed here using the program "less". Instead of having my data clutter and flood my screen, less seems like a better option.

Menu 2
This is a cumulation of all the exploits used by the malicious actors. It is a lot and it is sorted by the highest threat rating score.


Menu 3
Option menu three is used to navigate the pie chart options. An analyst has the choice of generating an individual chart or both. 


It is always good practice to provide error feedback if the program fails to execute seamlessly.

The pie chart is dynamically generated once the pipeline is initiated. An analyst can choose any of the options to initiate the process of populating the pie chart with the data of interest, and displaying it on the monitor.  Below is an example of a dynamically generated pie chart with all information.

The pie chart below shows the top talkers, protocols, usernames, and passwords.



Made using matplotlib.

Menu 4
This menu option is a quick console overview of what was found when batch executed and initiated the unified processing pipeline. 

There are over four hundred file artifacts discovered. The data is viewed using the “ less” program, an analyst can use the built-in sort functionality to sort the data. 

Menu 5
An analyst can query an internet address or fully qualified domain name and search for more data related to that internet address. A "honeypot_Omaha_query_reoprt.txt"  is generated.


After some analysis I observed that the threat actor made twenty-eight attempts and it shows a lot of the malicious actors' detailed activities. An analyst can use this consolidated view to analyze the data all in one screen. It displays the behavior analysis, pattern, utc timestamps, a count of how many attempts were made, the threat actors credentials and more.

Attempt number five displays the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a failed login.

At attempt number eight, the threat actor used a different password. Attempt number nine shows the secure shell version used. An analyst can track session id, there are five recorded sessions made by the threat actor. 

A new connection and login were successfully established at attempt number ten and eleven, batch displays the fingerprint and login details

The malicious actor has gained access to the system. I observed multiple commands executed on attempt number thirteen, such as exporting of the “usr/local/sbin”. This is the location that contains the system administration program tools and daemons installed locally by the owner of the system. “uname” and "Busybox” are visible, this threat actor gained and exfiltrated a wealth of information about the compromised system. The threat actor is covering up its activities by using this command “rm -rf filter”. This command recursively deletes any file or folder that is named filter. The rm removes any shell commands used in a Linux operating system, -r stands for recursive, which is used to perform a deep granular deletion of data forcefully. I am going to make an educated guess**—**Basically, the threat actor is probing, gathering data, and cleaning up their tracks.

Connection lost on attempt number fifteen.

The malicious actor is now using a different password as displayed on attempt number sixteen. 

A failed attempt was logged on attempt number nineteen and the connection was lost at attempt number twenty. Another attempt to re-establish a connection was successful as observed on attempt number twenty-four. 

As an analyst, you are a step behind the threat actor and must follow whatever digital breadcrumbs they leave behind to understand their movements. Every action creates a pattern—often captured by the acronym “RIPLE” (Reconnaissance, Initial exploitation, Persistence-privilege escalation, Lateral movement, and Exfiltration of data). As I often say, if you throw a rock into a pond, it produces a ripple effect.

The relentless, defenseless assault on honeypot_omaha continued, as shown on attempt number twenty-six.

Connection lost again and the threat actor exited as displayed on the screen at attempt number twenty-eight. A summary report of the threat actors’ activities is generated below.

Reflecting back to the original questions at the beginning of the diary. How did the threat actor gain access to the system, what was exfiltrated, and how do I as an analyst go about gathering more data for further investigation?

Recalling from the previous discussions, cowrie is designed to be vulnerable, so the malicious actor was able to guess the username and password.

Summary report on the shell commands executed on honeypot_omaha is generated and displayed on the screen. 

The batch.py script performed a detailed query on the application programming interfaces of  cve.org, paloaltonetworks.com and ip-api.com to generate and correlate intelligence data related to a suspected system compromise. It displays the threat rating score, status code, associated exploits, attack intent, and mitigation strategies. The targeted endpoints are sorted by their threat rating score and displayed below.

Reconnaissance and script profiling reveal the behavioral fingerprints of automated malware, botnets, or exploit payloads when they first gain access to a compromised shell**—in this case,** captured by honeypot_omaha as a “cowrie.command.input” event. Always practice persistence defense in depth, principle of least privilege’ and continuous diagnostics and mitigation. 
As an analyst, I was inquisitive about the data and conducted Google research on the internet service provider called “Pptechnology limited” and the executed commands. Below is a description of the internet service provider and a breakdown of what each section of the command does:

PPTECHNOLOGY LIMITED: Often associated with the brand/network name PTechnology) is a corporate entity and network infrastructure holder that has appeared in cybersecurity research, threat intelligence reports, and UK corporate registries.
Corporate Profile & UK Registration

Company Status: According to UK Companies House records, PPTECHNOLOGY LIMITED (Company Number: 12176225) was incorporated on August 27, 2019, and was officially dissolved on December 23, 2025.
Registered Address: It was registered at a mass-registration virtual office address in London (35 Firs Avenue)—a location known for hosting thousands of distinct corporate entities.
Registered Nature of Business: Officially classified under SIC code 96090 (Other service activities not elsewhere classified).

Threat Intelligence Context

In cybersecurity investigations (such as threat-hunting reports tracking offshore or "bulletproof-style" hosting infrastructure—notably research by firms like Team Cymru examining networks associated with anonymous hosting, ignore-DMCA setups, and malicious campaigns like Jingle Shells), PPTECHNOLOGY LIMITED has surfaced in analyses of proxy infrastructure:

Shell/Paper Companies: Security researchers have identified that shell and dormant UK entities like PPTECHNOLOGY LIMITED are frequently used as corporate facades or administrative holders for IP space and backend infrastructure associated with high-privacy or quasi-anonymous hosting environments.

Fraud Risk Scoring: Due to the nature of the IP blocks assigned to or historically associated with it, security scoring engines (like Scamalytics or VirusTotal) often flag traffic originating from these ranges as carrying higher risk or anonymity traits.

Note: The analysis above was performed by the analyst, using Google.com solely to research the internet service provider and executed commands. 
-----------
Guy Bruneau IPSS Inc.
My GitHub Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu

1 Comments

Published: 2026-09-01

Guildma (Astaroth) malware infection from Brazilian Portuguese email

Introduction

On Monday 2026-08-31, I used a link from a malicious Brazilian Portuguese email to infect a Windows host in my lab. This was a Guildma (Astaroth) malware infection.

The link from the email is geofenced for Brazil, meaning that it would only deliver the malware if I checked it from a Brazil-based IP address. Otherwise, it would send a legitimate installer (in this case for Android Studio) and not the malware. Furthermore, my web browser and operating system needed to use Brazilian Portuguese language settings and Brazil regional settings.

The initial downloaded file was a zip archive that contained a Windows shortcut. The shortcut retrieved content from a web server and saved it as an alternate data stream to a file created under the user's AppData\Local\Temp directory. This alternate data stream contained a 64-bit DLL file that doesn't appear to be malicious, but it was used to retrieve and install an AutoIt package for Guildma malware.

Today's diary shares indicators from the activity. Of note, many of the specific indicators like some of the SHA-256 hashes appear to be unique for this particular infection.

Images From the Infection


Shown above: Screenshot of the email.


Shown above: Malicious file downloaded from link in the email.


Shown above: Traffic from the infection filtered in Wireshark.


Shown above: Malware persistent on the infected Windows host.

Indicators of the Activity

Select headers from the email:

  • Received: from relatorio01a.colombstracciatella.cfd (unknown [185.254.222.105]) [information removed]; Wed, 26 Aug 2026 22:01:41 +0000 (UTC)
  • Sender: "Contrato Via Docusing" <[email protected][.]cfd>
  • Date: Wed, 26 Aug 2026 19:01:16 -0300
  • Subject: Assine com o Docusing: CONTRATO_ASSINATURA_FINAL.40572684.BPSE.CONTRATOS.DIGITAIS.pdf

Link from the message text: 

  • hxxps[:]//sistema-ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net/ 

Downloaded zip archive and extracted Windows shortcut:

SHA-256 hash: cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869

  • File size: 1,661 bytes
  • File name: 868283789726483.zip
  • File type: Zip archive data, at least v2.0 to extract

SHA-256 hash: 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911

  • File size: 1,553 bytes
  • File name: 868283789726483.lNk
  • File type: MS Windows shortcut

DLL saved as an alternate data stream during the infection, doesn't appear to be malicious:

SHA-256 hash: a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca

  • File size: 266,242 bytes
  • File type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows
  • File location: C:\Users\[username]\AppData\Local\Temp\n1LUQ7.log:h6JSb

Compiled AutoIt script for the persistent Guildma malware:

SHA-256 hash: f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4

  • File size: 277,874 bytes
  • File type: Data
  • File location: C:\Users\Public\Libraries\.cache\PLAX\Beatz.LEDPRO.09662.8729.422.log

Domains the infected Windows host communicated with over HTTPS (TCP port 443):

  • ekg3h4htc0h0ggdh.canadacentral-01.azurewebsites[.]net
  • plosancol.aguamammillaria[.]cfd
  • crironxil.aguasedum[.]cfd

TCP traffic to another domain:

  • tcp[:]//omzagdmspc.a.pinggy[.]link:21601/

Note: I saw HTTPS traffic to WhatsApp and GitHub domains later during this infection, but those are legitimate domains, so I didn't include them in this write-up. A previous article has noted this campaign abusing GitHub, so I've included the mention here. 

Bradley Duncan
brad [at] malware-traffic-analysis.net

0 Comments