NCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windows
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Microsoft has patched a large number of vulnerabilities in Windows. An attacker can exploit the vulnerabilities to conduct attacks that may result in the damage categories described in the table below. The most severe vulnerabilities have been assigned the identifiers CVE-2026-59124, CVE-2026-62815, CVE-2026-62878, CVE-2026-62893 and CVE-2026-65791 and are located in Telephony Service, QUIC, DNS Server, Capability Access Management Service, and iSCSI Target Service respectively. Attackers with access to these services may be able to execute code or gain access to the vulnerable system without prior authentication. In addition to these severe vulnerabilities, more than 230 vulnerabilities have been patched, all varying in severity from moderate to high/critical. Due to the nature and scope of these updates, the NCSC advises prioritizing the deployment of these updates.
Windows Accessibility Infrastructure (ATBroker.exe): |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-61358 | 7.80 | Privilege escalation | |----------------|------|-------------------------------------| Windows Kernel: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-54113 | 7.50 | Denial-of-Service | | CVE-2026-61930 | 7.80 | Privilege escalation | | CVE-2026-62737 | 7.80 | Privilege escalation | | CVE-2026-61929 | 7.00 | Privilege escalation | | CVE-2026-62708 | 6.40 | Privilege escalation | | CVE-2026-62749 | 7.00 | Privilege escalation | | CVE-2026-62780 | 7.00 | Privilege escalation | | CVE-2026-62788 | 7.00 | Privilege escalation | | CVE-2026-65773 | 7.80 | Privilege escalation | |----------------
CSIRTS triage
- What
- Multiple vulnerabilities in Windows services including Telephony, QUIC, DNS Server, Capability Access Management, and iSCSI Target Service allow code execution or unauthenticated access.
- Who is affected
- Windows deployments running vulnerable versions of the affected services.
- Urgency
- Immediate patching required; vulnerabilities are actively exploited and cover critical services with remote code execution impact.
- Action
- Deploy Microsoft's latest Windows security updates immediately, prioritizing the five named CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows
Get an email when a new Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0284
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-591241.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-628151.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-628781.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-628932.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 85% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657910.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-613583.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-541131.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-619302.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-627372.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 86% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-619291.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
Referenced CVEs
+184 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalGHSA-92f5-vc22-8j33: Microsoft QUIC: Remote Code Execution Vulnerabilityghsa
- critical[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilitiescert-bund
- unknownexploitedMicrosoft Monthly Security Update (August 2026)hkcert
- unknownexploitedSecurity Alert: Microsoft Releases August 2026 Security Updatesjpcert
- unknownMultiple vulnerabilities in Microsoft Azure (August 12, 2026)cert-fr-avis
- unknownexploitedMultiple vulnerabilities in Microsoft Windows (August 12, 2026)cert-fr-avis
- highCVE-2026-71331: Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attest…nvd
- mediumCVE-2026-70348: Improper link resolution before file access ('link following') in Windows Management Services …nvd
- highCVE-2026-70347: Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privi…nvd
- highCVE-2026-70346: Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate priv…nvd
- highCVE-2026-70345: Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privi…nvd
- highCVE-2026-70344: Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate priv…nvd
Recent advisories for Microsoft Windows
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEU] [kritisch] Microsoft Windows: Mehrere Schwachstellencert-bund · 2026-09-09
- unknownexploitedNCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl · 2026-09-09
- unknownexploitedMultiples vulnérabilités dans Microsoft Windows (09 septembre 2026)cert-fr-avis · 2026-09-09
- unknownNCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl · 2026-09-08
- highCVE-2026-81353: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
- highCVE-2026-81352: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
More from NCSC-NL Advisories
- unknownNCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOS2026-09-11
- unknownNCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS2026-09-10
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09