Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4843 articles · 212607 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-69276PATCHED
Microsoft · Windows 10 Version 1607

Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability

Description

Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 160710.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows 10 version 21h2mitre_affected90%
microsoftwindows server 2012 r2 (server core installation)mitre_affected90%
microsoftwindows server 2012 r2mitre_affected90%
microsoftwindows 10 versionmitre_affected90%
microsoftwindows server 2012 (server core installation)mitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69276(vendor-advisory, patch)

Related News (2 articles)

Tier C
VulDB4h ago
CVE-2026-69276 | Microsoft Windows up to Server 2025 UxTheme Library uxtheme.dll integer underflow
→ No new info (linked only)
Tier A
Microsoft MSRC9h ago
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.0.14393.951210.0.17763.924510.0.19044.772510.0.19045.772510.0.22631.758210.0.26100.944510.0.26200.944510.0.28000.29546.2.9200.263496.3.9600.2339710.0.20348.562210.0.26100.33438
CWECWE-191, CWE-122
PublishedSep 8, 2026
Last enriched6h ago
Trending Score59
Source articles3
Independent3
Info Completeness7/14
Missing: title, description, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85880EXPKEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Trending: 146
HIGHCVE-2026-81963EXPKEV
Windows Update Stack Elevation of Privilege Vulnerability
Trending: 143
HIGHCVE-2026-63520EXPKEV
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 72
CRITICALCVE-2026-70352
Azure AI Language Elevation of Privilege Vulnerability
Trending: 68
CRITICALCVE-2026-62916
Microsoft Entra ID Elevation of Privilege Vulnerability
Trending: 64

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 8, 2026
Discovered by ZDM
Sep 8, 2026
Patch Available
Sep 8, 2026