Executive and developer triage of Microsoft's September 2026 Patch Tuesday: 79 CVEs filtered down to the critical actively exploited zero-days.
| CVE Identifier | Subsystem / Component | Impact | CVSS | In-The-Wild Exploitation? |
|---|---|---|---|---|
| CVE-2024-30051 | Desktop Window Manager | Elevation of Privilege | 7.8 High | YES (In-The-Wild) |
| CVE-2024-38014 | Windows Installer | Elevation of Privilege | 7.8 High | No |
| CVE-2024-38018 | Windows Hyper-V | Remote Code Execution | 8.5 High | No |
| CVE-2024-38119 | Windows MSHTML Platform | Security Feature Bypass | 5.4 Medium | YES (Prior Campaign) |
Read our line-by-line decompiled C source code analysis showing how an unchecked 32-bit addition allowed local malware to corrupt kernel heap pool structures.