How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
July 2026 Patch Tuesday: Microsoft fixed 571 vulnerabilities, 58 of them Critical. 3 were already being exploited. Released Tue 14 Jul 2026.
- 571vulnerabilities fixed
- 58Critical
- 3exploited before the fix
- 1publicly disclosed
- 5now on CISA KEV
By type: 250 elevation of privilege, 143 remote code execution, 102 information disclosure, 35 denial of service, 17 security feature bypass, 16 spoofing, 8 tampering.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2026-50522 | Microsoft SharePoint Remote Code Execution | Critical | 9.8 | On CISA KEV federal deadline 25 Jul |
CVE-2026-58644 | Microsoft SharePoint Remote Code Execution | Critical | 9.8 | Exploited On CISA KEV federal deadline 19 Jul |
CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass | Critical | 9.1 | On CISA KEV federal deadline 21 Aug |
CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege | Important | 7.8 | Exploited On CISA KEV federal deadline 28 Jul |
CVE-2026-50661 | Windows BitLocker Security Feature Bypass | Important | 6.1 | Publicly disclosed |
CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege | Moderate | 5.3 | Exploited On CISA KEV federal deadline 17 Jul |
Critical (58)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2026-57092 | Microsoft Windows VMSwitch Elevation of Privilege | Elevation of Privilege | 9.9 |
CVE-2026-50518 | Windows DHCP Server Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-50522 | Microsoft SharePoint Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-54117 | Microsoft SQL Server Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-54118 | Microsoft SQL Server Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-55010 | Minecraft Bedrock Dedicated Server Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-55944 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-56159 | DHCP Server Service Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-56188 | Windows Server Network driver Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-58644 | Microsoft SharePoint Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-48561 | Microsoft Edge Copilot Remote Code Execution | Remote Code Execution | 9.6 |
CVE-2026-50380 | Windows GDI+ Remote Code Execution | Remote Code Execution | 9.6 |
CVE-2026-55008 | Microsoft Exchange Server Spoofing | Spoofing | 9.6 |
CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass | Security Feature Bypass | 9.1 |
CVE-2026-48564 | DHCP Server Service Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-50370 | DHCP Server Service Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-50382 | DirectX Graphics Kernel Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-50444 | Windows Server Update Service (WSUS) Elevation of Privilege | Elevation of Privilege | 8.8 |
CVE-2026-50474 | Remote Desktop Client Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-54121 | Active Directory Certificate Services Elevation of Privilege | Elevation of Privilege | 8.8 |
CVE-2026-54982 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-54999 | Windows TCP/IP Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-57087 | Microsoft Windows Media Foundation Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-57090 | Microsoft Windows Media Foundation Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-57094 | Microsoft Windows Media Foundation Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-58608 | Windows Print Spooler Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-54128 | Windows DHCP Client Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-54992 | Microsoft Message Queuing Queue Manager Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-55045 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-50680 | Windows Hyper-V Elevation of Privilege | Elevation of Privilege | 8.2 |
CVE-2026-49164 | Windows Active Directory Domain Services Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-50694 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-54995 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-42982 | Windows Secure Kernel Mode Elevation of Privilege | Elevation of Privilege | 7.8 |
CVE-2026-49796 | Windows GDI+ Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-50301 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-50314 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-50327 | Windows Media Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-50467 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-50655 | Microsoft Windows Media Foundation Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55011 | Microsoft Defender Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55012 | Microsoft Defender Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55018 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55022 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55033 | Microsoft Word Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55043 | Microsoft PowerPoint Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55049 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55056 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55120 | Microsoft PowerPoint Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55123 | Microsoft PowerPoint Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55127 | Microsoft Word Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55129 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55132 | Microsoft Word Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-55140 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-56189 | Microsoft Windows Media Foundation Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-58542 | Windows Media Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-54127 | Windows Hyper-V Elevation of Privilege | Elevation of Privilege | 7.4 |
CVE-2026-50392 | Windows Secure Kernel Mode Elevation of Privilege | Elevation of Privilege | 7.0 |
Added to CISA KEV in July 2026 (26)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password | 29 Jul | 1 Aug 2026 | Known |
CVE-2025-68686 | Fortinet FortiOS | Exposure of Sensitive Information to an Unauthorized Actor | 27 Jul | 10 Aug 2026 | |
CVE-2026-16812 | Arista VeloCloud Orchestrator | On-Prem OS Command Injection | 27 Jul | 30 Jul 2026 | |
CVE-2026-16232 | Check Point SmartConsole | Improper Authentication | 22 Jul | 25 Jul 2026 | |
CVE-2026-50522 | Microsoft SharePoint | Deserialization of Untrusted Data Vulnerability | 22 Jul | 25 Jul 2026 | |
CVE-2021-27137 | DD-WRT DD-WRT | DD-WRT Stack-Based Buffer Overflow | 21 Jul | 24 Jul 2026 | |
CVE-2026-0770 | Langflow Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere | 21 Jul | 24 Jul 2026 | |
CVE-2026-60137 | WordPress Core | SQL Injection | 21 Jul | 4 Aug 2026 | |
CVE-2026-63030 | WordPress Core | Interpretation Conflict | 21 Jul | 24 Jul 2026 | |
CVE-2026-25089 | Fortinet FortiSandbox | OS Command Injection | 16 Jul | 19 Jul 2026 | |
CVE-2026-39808 | Fortinet FortiSandbox | OS Command Injection | 16 Jul | 19 Jul 2026 | |
CVE-2026-58644 | Microsoft SharePoint | Deserialization of Untrusted Data | 16 Jul | 19 Jul 2026 | |
CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 | Overly Restrictive Account Lockout Mechanism | 15 Jul | 29 Jul 2026 | |
CVE-2026-46817 | Oracle E-Business Suite | Improper Privilege Management | 15 Jul | 18 Jul 2026 | |
CVE-2026-15409 | SonicWall SMA1000 Appliances | Server-Side Request Forgery | 14 Jul | 17 Jul 2026 | Known |
CVE-2026-15410 | SonicWall SMA1000 Appliances | Code Injection | 14 Jul | 17 Jul 2026 | Known |
CVE-2026-56155 | Microsoft Active Directory Federation Services | Insufficient Granularity of Access Control Vulnerability | 14 Jul | 28 Jul 2026 | |
CVE-2026-56164 | Microsoft SharePoint Server | Missing Authentication for Critical Function | 14 Jul | 17 Jul 2026 | |
CVE-2008-4128 | Cisco IOS | Cross-Site Request Forgery | 13 Jul | 16 Jul 2026 | |
CVE-2026-48939 | iCagenda iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type | 10 Jul | 13 Jul 2026 | |
CVE-2026-56291 | Balbooa Forms | Unrestricted Upload of File with Dangerous Type | 10 Jul | 13 Jul 2026 | |
CVE-2026-48282 | Adobe ColdFusion | Path Traversal | 7 Jul | 10 Jul 2026 | |
CVE-2026-48908 | JoomShaper SP Page Builder | Unrestricted Upload of File with Dangerous Type | 7 Jul | 10 Jul 2026 | |
CVE-2026-55255 | Langflow Langflow | Langflow Authorization Bypass Through User-Controlled Key | 7 Jul | 10 Jul 2026 | |
CVE-2026-56290 | Joomlack Page Builder | Improper Access Control | 7 Jul | 10 Jul 2026 | |
CVE-2026-45659 | Microsoft SharePoint Server | Deserialization of Untrusted Data | 1 Jul | 4 Jul 2026 | Known |
All 571 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2026-57092 | Windows VMSwitch | Microsoft Windows VMSwitch Elevation of Privilege | Critical | 9.9 |
CVE-2026-50518 | Windows DHCP Server | Windows DHCP Server Remote Code Execution | Critical | 9.8 |
CVE-2026-50522 | Microsoft Office SharePoint | Microsoft SharePoint Remote Code Execution | Critical | 9.8 |
CVE-2026-54117 | SQL Server | Microsoft SQL Server Remote Code Execution | Critical | 9.8 |
CVE-2026-54118 | SQL Server | Microsoft SQL Server Remote Code Execution | Critical | 9.8 |
CVE-2026-55010 | Minecraft Bedrock Dedicated Server | Minecraft Bedrock Dedicated Server Remote Code Execution | Critical | 9.8 |
CVE-2026-55944 | Microsoft Dynamics NAV | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution | Critical | 9.8 |
CVE-2026-56159 | Windows DHCP Server | DHCP Server Service Remote Code Execution | Critical | 9.8 |
CVE-2026-56188 | Windows Server Network driver | Windows Server Network driver Remote Code Execution | Critical | 9.8 |
CVE-2026-58644 | Microsoft Office SharePoint | Microsoft SharePoint Remote Code Execution | Critical | 9.8 |
CVE-2026-48561 | Copilot Chat (Microsoft Edge) | Microsoft Edge Copilot Remote Code Execution | Critical | 9.6 |
CVE-2026-50380 | Windows GDI+ | Windows GDI+ Remote Code Execution | Critical | 9.6 |
CVE-2026-55008 | Microsoft Exchange Server | Microsoft Exchange Server Spoofing | Critical | 9.6 |
CVE-2026-55040 | Microsoft Office SharePoint | Microsoft SharePoint Server Security Feature Bypass | Critical | 9.1 |
CVE-2026-48564 | Windows DHCP Server | DHCP Server Service Remote Code Execution | Critical | 8.8 |
CVE-2026-50370 | Windows DHCP Server | DHCP Server Service Remote Code Execution | Critical | 8.8 |
CVE-2026-50382 | Windows DirectX | DirectX Graphics Kernel Remote Code Execution | Critical | 8.8 |
CVE-2026-50444 | Windows Server Update Service | Windows Server Update Service (WSUS) Elevation of Privilege | Critical | 8.8 |
CVE-2026-50474 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Critical | 8.8 |
CVE-2026-54121 | Active Directory Certificate Services (AD CS) | Active Directory Certificate Services Elevation of Privilege | Critical | 8.8 |
CVE-2026-54982 | Reliable Multicast Transport Driver (RMCAST) | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution | Critical | 8.8 |
CVE-2026-54999 | Windows TCP/IP | Windows TCP/IP Remote Code Execution | Critical | 8.8 |
CVE-2026-57087 | Microsoft Windows Media Foundation | Microsoft Windows Media Foundation Remote Code Execution | Critical | 8.8 |
CVE-2026-57090 | Microsoft Windows Media Foundation | Microsoft Windows Media Foundation Remote Code Execution | Critical | 8.8 |
CVE-2026-57094 | Microsoft Windows Media Foundation | Microsoft Windows Media Foundation Remote Code Execution | Critical | 8.8 |
CVE-2026-58608 | Windows Print Spooler Components | Windows Print Spooler Remote Code Execution | Critical | 8.8 |
CVE-2026-54128 | Windows DHCP Client | Windows DHCP Client Remote Code Execution | Critical | 8.4 |
CVE-2026-54992 | Windows Message Queuing Queue Manager | Microsoft Message Queuing Queue Manager Remote Code Execution | Critical | 8.4 |
CVE-2026-55045 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-50680 | Windows Hyper-V | Windows Hyper-V Elevation of Privilege | Critical | 8.2 |
CVE-2026-49164 | Active Directory Domain Services | Windows Active Directory Domain Services Remote Code Execution | Critical | 8.1 |
CVE-2026-50694 | Windows Secure Socket Tunneling Protocol (SSTP) | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution | Critical | 8.1 |
CVE-2026-54995 | Reliable Multicast Transport Driver (RMCAST) | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution | Critical | 8.1 |
CVE-2026-42982 | Windows Secure Kernel Mode | Windows Secure Kernel Mode Elevation of Privilege | Critical | 7.8 |
CVE-2026-49796 | Windows GDI+ | Windows GDI+ Remote Code Execution | Critical | 7.8 |
CVE-2026-50301 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-50314 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-50327 | Windows Media | Windows Media Remote Code Execution | Critical | 7.8 |
CVE-2026-50467 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-50655 | Windows Media | Microsoft Windows Media Foundation Remote Code Execution | Critical | 7.8 |
CVE-2026-55011 | Microsoft Defender | Microsoft Defender Remote Code Execution | Critical | 7.8 |
CVE-2026-55012 | Microsoft Defender | Microsoft Defender Remote Code Execution | Critical | 7.8 |
CVE-2026-55018 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-55022 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-55033 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 7.8 |
CVE-2026-55043 | Microsoft Office PowerPoint | Microsoft PowerPoint Remote Code Execution | Critical | 7.8 |
CVE-2026-55049 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-55056 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-55120 | Microsoft Office PowerPoint | Microsoft PowerPoint Remote Code Execution | Critical | 7.8 |
CVE-2026-55123 | Microsoft Office PowerPoint | Microsoft PowerPoint Remote Code Execution | Critical | 7.8 |
CVE-2026-55127 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 7.8 |
CVE-2026-55129 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-55132 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 7.8 |
CVE-2026-55140 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-56189 | Microsoft Windows Media Foundation | Microsoft Windows Media Foundation Remote Code Execution | Critical | 7.8 |
CVE-2026-58542 | Windows Media | Windows Media Remote Code Execution | Critical | 7.8 |
CVE-2026-54127 | Windows Hyper-V | Windows Hyper-V Elevation of Privilege | Critical | 7.4 |
CVE-2026-50392 | Windows Secure Kernel Mode | Windows Secure Kernel Mode Elevation of Privilege | Critical | 7.0 |
CVE-2026-42990 | SQL Server ODBC driver | SQL Server ODBC driver Elevation of Privilege | Important | 9.8 |
CVE-2026-49172 | Windows FTP Service | Windows FTP Service Remote Code Execution | Important | 9.8 |
CVE-2026-50447 | Windows Message Queuing | Windows Message Queuing Service (MSMQ) Remote Code Execution | Important | 9.8 |
CVE-2026-54990 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Important | 9.8 |
CVE-2026-56190 | Windows RDP | Remote Desktop Protocol Remote Code Execution | Important | 9.8 |
CVE-2026-49798 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 9.3 |
CVE-2026-41109 | GitHub Copilot and Visual Studio | GitHub Copilot and Visual Studio Code Security Feature Bypass | Important | 8.8 |
CVE-2026-47295 | SQL Server | Microsoft SQL Server Elevation of Privilege | Important | 8.8 |
CVE-2026-47300 | ASP.NET Core | ASP.NET Core Elevation of Privilege | Important | 8.8 |
CVE-2026-47301 | Microsoft Configuration Manager | Configuration Manager Elevation of Privilege | Important | 8.8 |
CVE-2026-47303 | ASP.NET Core | ASP.NET Core Elevation of Privilege | Important | 8.8 |
CVE-2026-47632 | Azure Connected Machine Agent | Azure Connected Machine Agent Elevation of Privilege | Important | 8.8 |
CVE-2026-49178 | Active Directory Domain Services | Windows Active Directory Domain Services Remote Code Execution | Important | 8.8 |
CVE-2026-49795 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 8.8 |
CVE-2026-50342 | Windows MIDI Service Module | Windows MIDI Service Module Elevation of Privileges | Important | 8.8 |
CVE-2026-50360 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 8.8 |
CVE-2026-50369 | Windows Remote Desktop Services | Windows Remote Desktop Services Elevation of Privilege | Important | 8.8 |
CVE-2026-50385 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 8.8 |
CVE-2026-50398 | Windows Media | Windows Media Elevation of Privilege | Important | 8.8 |
CVE-2026-50413 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 8.8 |
CVE-2026-50438 | Window PC Manager | Microsoft PC Manager Elevation of Privilege | Important | 8.8 |
CVE-2026-50477 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 8.8 |
CVE-2026-50489 | Windows Win32K | Win32k Elevation of Privilege | Important | 8.8 |
CVE-2026-50663 | Age of Empires II: Definitive Edition Game | Game: Age of Empires II: Definitive Edition Remote Code Execution | Important | 8.8 |
CVE-2026-50666 | Windows Remote Access Connection Manager | Windows Remote Access Elevation of Privilege | Important | 8.8 |
CVE-2026-50670 | Windows Kernel | Windows Win32k Elevation of Privilege | Important | 8.8 |
CVE-2026-50687 | Windows Kernel | Windows Win32k Elevation of Privilege | Important | 8.8 |
CVE-2026-50692 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 8.8 |
CVE-2026-54107 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 8.8 |
CVE-2026-55002 | SQL Server | Microsoft SQL Server Elevation of Privilege | Important | 8.8 |
CVE-2026-55005 | Microsoft Exchange Server | Microsoft Exchange Server Remote Code Execution | Important | 8.8 |
CVE-2026-55052 | Microsoft Office SharePoint | Microsoft SharePoint Elevation of Privilege | Important | 8.8 |
CVE-2026-56194 | Windows Network File System | Windows NFS Server Elevation of Privilege | Important | 8.8 |
CVE-2026-56196 | Windows Admin Center | Windows Admin Center (WAC) Remote Code Execution | Important | 8.8 |
CVE-2026-56197 | Windows Admin Center | Windows Admin Center (WAC) Remote Code Execution | Important | 8.8 |
CVE-2026-56642 | Microsoft Fabric Data Warehouse | Microsoft Fabric Data Warehouse Remote Code Execution | Important | 8.8 |
CVE-2026-56647 | Windows Remote Access Service Infrastructure | Windows Remote Access Service Infrastructure Elevation of Privilege | Important | 8.8 |
CVE-2026-57102 | Visual Studio Code | Visual Studio Code Security Feature Bypass | Important | 8.8 |
CVE-2026-57969 | Azure CycleCloud | Azure CycleCloud Elevation of Privilege | Important | 8.8 |
CVE-2026-58277 | Microsoft Office SharePoint | Microsoft SharePoint Elevation of Privilege | Important | 8.8 |
CVE-2026-58534 | Microsoft Input Method Editor (IME) | Windows Input Method Editor (IME) Elevation of Privilege | Important | 8.8 |
CVE-2026-58594 | Windows RDP | Remote Desktop Client Remote Code Execution | Important | 8.8 |
CVE-2026-58626 | Windows Remote Desktop Services | Windows Remote Desktop Services Remote Code Execution | Important | 8.8 |
CVE-2026-50340 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 8.5 |
CVE-2026-49184 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 8.4 |
CVE-2026-50520 | Visual Studio Code | Visual Studio Code Remote Code Execution | Important | 8.4 |
CVE-2026-54122 | Windows GDI+ | Windows GDI+ Remote Code Execution | Important | 8.4 |
CVE-2026-50338 | Azure Spring Apps | Azure Spring Apps Elevation of Privilege | Important | 8.2 |
CVE-2026-50429 | Windows Kernel | Windows Kernel Information Disclosure | Important | 8.2 |
CVE-2026-50528 | .NET | .NET Security Feature Bypass | Important | 8.2 |
CVE-2026-42900 | Microsoft Windows App Store | Microsoft Windows App Store Elevation of Privilege | Important | 8.1 |
CVE-2026-47304 | .NET | .NET Security Feature Bypass | Important | 8.1 |
CVE-2026-50439 | Windows Message Queuing Queue Manager | Microsoft Message Queuing Queue Manager Remote Code Execution | Important | 8.1 |
CVE-2026-50460 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 8.1 |
CVE-2026-50487 | Windows DNS | Windows DNS Client Elevation of Privilege | Important | 8.1 |
CVE-2026-50686 | Windows OLE | Windows OLE Remote Code Execution | Important | 8.1 |
CVE-2026-56169 | Windows Admin Center | Windows Admin Center Elevation of Privilege | Important | 8.1 |
CVE-2026-56186 | Windows Schannel | Windows Secure Channel Information Disclosure | Important | 8.1 |
CVE-2026-58595 | Microsoft Bing App for IOS | Microsoft Bing App for IOS Spoofing | Important | 8.1 |
CVE-2026-58617 | Microsoft 365 Copilot for iOS | M365 Copilot for iOS Elevation of Privilege | Important | 8.1 |
CVE-2026-40400 | Windows PowerShell | Windows PowerShell Remote Code Execution | Important | 8.0 |
CVE-2026-42975 | Windows Bluetooth Port Driver | Windows Bluetooth Port Driver Remote Code Execution | Important | 8.0 |
CVE-2026-49169 | Role: DNS Server | Windows DNS Server Remote Code Execution | Important | 8.0 |
CVE-2026-50365 | Windows RPC API | Remote Access Management service/API (RPC server) Elevation of Privilege | Important | 8.0 |
CVE-2026-50502 | Windows Event Logging Service | Windows Event Logging Service Remote Code Execution | Important | 8.0 |
CVE-2026-50683 | Windows DHCP Server | Windows DHCP Client Elevation of Privilege | Important | 8.0 |
CVE-2026-58647 | Power BI | Microsoft PowerBI Report Server Spoofing | Important | 8.0 |
CVE-2026-44800 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 7.8 |
CVE-2026-47290 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2026-47305 | Visual Studio | Visual Studio Remote Code Execution | Important | 7.8 |
CVE-2026-47642 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-48581 | Microsoft Surface | Surface Broker SDMA Elevation of Privilege | Important | 7.8 |
CVE-2026-49166 | Microsoft Printer Drivers | Windows Print Configuration Elevation of Privilege | Important | 7.8 |
CVE-2026-49170 | Windows StateRepository API | Windows StateRepository API Server file Elevation of Privilege | Important | 7.8 |
CVE-2026-49173 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-49175 | Windows DNS | Windows DNS Client Elevation of Privilege | Important | 7.8 |
CVE-2026-49176 | Windows WalletService | Windows WalletService Elevation of Privilege | Important | 7.8 |
CVE-2026-49783 | Windows Secure Boot | Secure Boot Security Feature Bypass | Important | 7.8 |
CVE-2026-49792 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 7.8 |
CVE-2026-49793 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 7.8 |
CVE-2026-49797 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-49800 | Windows Web Proxy Auto-Discovery Protocol (WPAD) | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege | Important | 7.8 |
CVE-2026-49808 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50293 | Windows Internal Task Bar | Windows Internal Task Bar Elevation of Privilege | Important | 7.8 |
CVE-2026-50305 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.8 |
CVE-2026-50306 | Windows TCP/IP | Windows TCP/IP Elevation of Privilege | Important | 7.8 |
CVE-2026-50308 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50309 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50311 | Windows Server | Windows Server Elevation of Privilege | Important | 7.8 |
CVE-2026-50313 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50315 | Windows Image Acquisition | Windows Image Acquisition Elevation of Privilege | Important | 7.8 |
CVE-2026-50317 | Windows Operating Systems | Windows Operating Systems Elevation of Privilege | Important | 7.8 |
CVE-2026-50318 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-50321 | Windows USB Driver | Windows USB Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-50326 | Windows Unified Consent System | Windows Unified Consent System Elevation of Privilege | Important | 7.8 |
CVE-2026-50329 | Windows Kernel | Microsoft DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-50331 | Windows Application Model | Windows Application Model Core API Elevation of Privilege | Important | 7.8 |
CVE-2026-50332 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50333 | Windows Spaceport.sys | Windows Spaceport.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-50335 | Windows Operating Systems | Windows Operating Systems Elevation of Privilege | Important | 7.8 |
CVE-2026-50336 | Windows Media | Windows Media Elevation of Privilege | Important | 7.8 |
CVE-2026-50337 | Windows Notification | Windows Notification Elevation of Privilege | Important | 7.8 |
CVE-2026-50343 | Microsoft Install Service | Microsoft Install Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50344 | Windows OLE | Windows OLE Elevation of Privilege | Important | 7.8 |
CVE-2026-50346 | RPC Runtime | Netlogon RPC Elevation of Privilege | Important | 7.8 |
CVE-2026-50347 | Windows Data.dll | Windows Data.dll Remote Code Execution | Important | 7.8 |
CVE-2026-50351 | Windows Audio Compression Manager (ACM) | Windows Audio Compression Manager (ACM) Elevation of Privilege | Important | 7.8 |
CVE-2026-50353 | Windows DirectX | DirectX Graphics Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50357 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-50361 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.8 |
CVE-2026-50362 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 7.8 |
CVE-2026-50363 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 7.8 |
CVE-2026-50367 | Windows Sensor Data Service | Windows Sensor Data Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50373 | Microsoft Windows Search Component | Windows Search Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50378 | Windows Key Guard | Windows Key Guard Elevation of Privilege | Important | 7.8 |
CVE-2026-50386 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50387 | Windows GDI | Windows GDI Elevation of Privilege | Important | 7.8 |
CVE-2026-50388 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50391 | Windows Group Policy | Windows Group Policy Elevation of Privilege | Important | 7.8 |
CVE-2026-50399 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50400 | Windows App Installer | Windows App Package Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-50402 | Windows NTFS | NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-50405 | Windows Filtering Platform (WFP) | Windows Filtering Platform Elevation of Privilege | Important | 7.8 |
CVE-2026-50407 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-50412 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-50417 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50421 | Windows Connected User Experiences and Telemetry | Windows Connected User Experiences and Telemetry Elevation of Privilege | Important | 7.8 |
CVE-2026-50422 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-50423 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50425 | Windows Internal System User Profile | Windows Internal System User Profile Elevation of Privilege | Important | 7.8 |
CVE-2026-50427 | Content Delivery Manager | Content Delivery Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-50433 | Windows Media | Windows Media Elevation of Privilege | Important | 7.8 |
CVE-2026-50435 | Windows Overlay Filter | Windows Overlay Filter Elevation of Privilege | Important | 7.8 |
CVE-2026-50436 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50440 | Windows Audio Service | Windows Audio Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50441 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-50448 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50450 | Windows Wireless Wide Area Network Service | Windows Network Connections Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50454 | Windows User Interface Core | Windows User Interface Core Elevation of Privilege | Important | 7.8 |
CVE-2026-50457 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.8 |
CVE-2026-50458 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.8 |
CVE-2026-50461 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50462 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-50466 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.8 |
CVE-2026-50469 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-50471 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50476 | Microsoft Windows | Windows Network Connections Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50478 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50479 | Windows USB Hub Driver | Windows USB Hub Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-50480 | Windows Web Proxy Auto-Discovery Protocol (WPAD) | Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege | Important | 7.8 |
CVE-2026-50484 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50486 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.8 |
CVE-2026-50488 | Windows Clipboard User Service | Clipboard User Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50493 | Windows Graphics Kernel | DirectX Graphics Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50494 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-50498 | Windows Universal Disk Format File System Driver (UDFS) | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege | Important | 7.8 |
CVE-2026-50499 | Windows Print Spooler Components | Windows Print Spooler Elevation of Privilege | Important | 7.8 |
CVE-2026-50501 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 7.8 |
CVE-2026-50509 | Windows Wireless Wide Area Network Service | Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege | Important | 7.8 |
CVE-2026-50510 | Github Copilot | GitHub Copilot Remote Code Execution | Important | 7.8 |
CVE-2026-50646 | .NET Framework | .NET Framework Remote Code Execution | Important | 7.8 |
CVE-2026-50649 | .NET | .NET Remote Code Execution | Important | 7.8 |
CVE-2026-50650 | .NET Framework | .NET Framework Elevation of Privilege | Important | 7.8 |
CVE-2026-50665 | Microsoft Office | Microsoft Office Information Disclosure | Important | 7.8 |
CVE-2026-50667 | Windows NTFS | Windows Common Log File System Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-50673 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-50675 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-50676 | Windows Media | Windows Media Elevation of Privilege | Important | 7.8 |
CVE-2026-50677 | Windows Media | Windows Media Elevation of Privilege | Important | 7.8 |
CVE-2026-50679 | Microsoft Windows Search Component | Windows Search Service Elevation of Privilege | Important | 7.8 |
CVE-2026-50688 | Windows Kernel | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-50689 | Windows Clipboard Server | Windows Clipboard Server Elevation of Privilege | Important | 7.8 |
CVE-2026-50697 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-54109 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 7.8 |
CVE-2026-54112 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-54114 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-54115 | Windows Active Directory | Windows Message Queuing (MSMQ) Elevation of Privilege | Important | 7.8 |
CVE-2026-54124 | Windows Terminal | Windows Terminal Remote Code Execution | Important | 7.8 |
CVE-2026-54125 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.8 |
CVE-2026-54131 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-54986 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-54987 | Windows Overlay Filter | Windows Overlay Filter Elevation of Privilege | Important | 7.8 |
CVE-2026-54991 | Windows USB Print Driver | Windows USB Print Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-54993 | Microsoft Windows Media Foundation | Microsoft Windows Media Foundation Remote Code Execution | Important | 7.8 |
CVE-2026-55001 | Windows Active Directory | Active Directory Domain Services Elevation of Privilege | Important | 7.8 |
CVE-2026-55004 | Microsoft Printer Drivers | Windows Print Configuration Elevation of Privilege | Important | 7.8 |
CVE-2026-55006 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Important | 7.8 |
CVE-2026-55009 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Important | 7.8 |
CVE-2026-55014 | Windows Remote Help Defense | Windows Remote Help Defense Elevation of Privilege | Important | 7.8 |
CVE-2026-55017 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2026-55024 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55025 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55029 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55031 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55032 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-55036 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55037 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55038 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-55039 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55041 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55044 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55048 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55053 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55055 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-55058 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55125 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2026-55128 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-55130 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-55131 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55133 | Microsoft Office OneNote | Microsoft OneNote Remote Code Execution | Important | 7.8 |
CVE-2026-55134 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-55136 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55137 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55141 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55899 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55947 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55948 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-55949 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-56155 | Active Directory Federation Services (AD FS) | Active Directory Federation Services Elevation of Privilege | Important | 7.8 |
CVE-2026-56156 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-56175 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-56176 | Windows Win32K – GRFX | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-56182 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-56643 | Windows Kernel | DirectX Graphics Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-56644 | Windows Kernel | DirectX Graphics Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-56650 | Windows Network File System | Windows Network File System Elevation of Privilege | Important | 7.8 |
CVE-2026-57088 | Extensible Storage Engine (ESENT) | Extensible Storage Engine (ESENT) Elevation of Privilege | Important | 7.8 |
CVE-2026-57091 | Windows File History Service | Windows File History Service Elevation of Privilege | Important | 7.8 |
CVE-2026-57096 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege | Important | 7.8 |
CVE-2026-57107 | Windows Admin Center | Windows Admin Center Elevation of Privilege | Important | 7.8 |
CVE-2026-57968 | Windows Subsystem for Linux | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-58527 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.8 |
CVE-2026-58530 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 7.8 |
CVE-2026-58532 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-58536 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-58537 | Microsoft NAT Helper Components (ipnathlp.dll) | Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege | Important | 7.8 |
CVE-2026-58538 | Windows Bluetooth Service | Windows Bluetooth Service Elevation of Privilege | Important | 7.8 |
CVE-2026-58540 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-58541 | Windows DWM | Microsoft DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-58601 | Virtual Hard Disk (VHD) Miniport Driver | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | Important | 7.8 |
CVE-2026-58602 | Windows Kernel Mode Driver | Windows Kernel-Mode Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-58609 | Microsoft Graphics Component | Windows Graphics Component Remote Code Execution | Important | 7.8 |
CVE-2026-58610 | Microsoft Windows Media Foundation | Microsoft Windows Media Foundation Remote Code Execution | Important | 7.8 |
CVE-2026-58613 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-58618 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-58628 | Windows Wireless Networking | Windows Wireless Network Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-58631 | Windows Admin Center | Windows Admin Center (WAC) Remote Code Execution | Important | 7.8 |
CVE-2026-58632 | Windows Win32K | Windows Win32 Kernel Subsystem Elevation of Privilege | Important | 7.8 |
CVE-2026-58633 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-58634 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-58635 | Windows Narrator Braille | Windows Narrator Braille Elevation of Privilege | Important | 7.8 |
CVE-2026-58636 | Window PC Manager | Microsoft PC Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-40378 | Windows Local Security Authority Subsystem Service (LSASS) | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service | Important | 7.5 |
CVE-2026-45646 | ASP.NET Core | OData for ASP.NET and ASP.NET Core Denial of Service | Important | 7.5 |
CVE-2026-47296 | SQL Server | Microsoft SQL Server Elevation of Privilege | Important | 7.5 |
CVE-2026-47302 | .NET | .NET Denial of Service | Important | 7.5 |
CVE-2026-49171 | Microsoft Windows Speech | Windows Speech Runtime Elevation of Privilege | Important | 7.5 |
CVE-2026-49181 | Windows DHCP Client | Windows DHCP Client Elevation of Privilege | Important | 7.5 |
CVE-2026-49787 | Windows HTTP.sys | HTTP.sys Denial of Service | Important | 7.5 |
CVE-2026-49788 | HTTP/2 | HTTP/2 Denial of Service | Important | 7.5 |
CVE-2026-50304 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services Denial of Service | Important | 7.5 |
CVE-2026-50328 | Windows Server Update Service | Windows Server Update Service (WSUS) Tampering | Important | 7.5 |
CVE-2026-50330 | Remote Desktop Client | Windows Remote Desktop Client Elevation of Privilege | Important | 7.5 |
CVE-2026-50355 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services Denial of Service | Important | 7.5 |
CVE-2026-50368 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services Denial of Service | Important | 7.5 |
CVE-2026-50379 | Windows Media | Windows Media Elevation of Privilege | Important | 7.5 |
CVE-2026-50411 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services Denial of Service | Important | 7.5 |
CVE-2026-50414 | Windows Media | Windows Media Elevation of Privilege | Important | 7.5 |
CVE-2026-50424 | Windows Domain Controller | Windows Domain Controller Denial of Service | Important | 7.5 |
CVE-2026-50463 | Windows Kernel | Windows Kernel Information Disclosure | Important | 7.5 |
CVE-2026-50470 | Windows Network Policy Server SNMP | Windows Network Policy Server SNMP Information Disclosure | Important | 7.5 |
CVE-2026-50496 | Windows Network Policy Server SNMP | Windows Network Policy Server SNMP Information Disclosure | Important | 7.5 |
CVE-2026-50500 | Windows Netlogon | Windows Netlogon Elevation of Privilege | Important | 7.5 |
CVE-2026-50505 | Windows Message Queuing | Windows Message Queuing Service (MSMQ) Remote Code Execution | Important | 7.5 |
CVE-2026-50506 | ASP.NET Core | OData for ASP.NET and ASP.NET Core Denial of Service | Important | 7.5 |
CVE-2026-50524 | .NET Framework | .NET Framework Denial of Service | Important | 7.5 |
CVE-2026-50525 | .NET | .NET Denial of Service | Important | 7.5 |
CVE-2026-50527 | .NET Framework | .NET Framework Denial of Service | Important | 7.5 |
CVE-2026-50647 | Active Directory Federation Services (AD FS) | Active Directory Federation Server Denial of Service | Important | 7.5 |
CVE-2026-50648 | .NET Framework | .NET Framework Denial of Service | Important | 7.5 |
CVE-2026-50651 | .NET | .NET Denial of Service | Important | 7.5 |
CVE-2026-50652 | Azure Active Directory | Azure Active Directory Denial of Service | Important | 7.5 |
CVE-2026-50653 | Azure Active Directory | Azure Active Directory Denial of Service | Important | 7.5 |
CVE-2026-50685 | Windows DHCP Server | Windows DHCP Server Remote Code Execution | Important | 7.5 |
CVE-2026-50695 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services Denial of Service | Important | 7.5 |
CVE-2026-50696 | Windows Internet Key Exchange (IKE) Protocol | Internet Key Exchange (IKE) Protocol Denial of Service | Important | 7.5 |
CVE-2026-54119 | Windows Active Directory | Windows Active Directory Denial of Service | Important | 7.5 |
CVE-2026-54983 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services Denial of Service | Important | 7.5 |
CVE-2026-56170 | ASP.NET Core | ASP.NET Core Denial of Service | Important | 7.5 |
CVE-2026-56648 | Windows Network File System | Windows NFS Server Elevation of Privilege | Important | 7.5 |
CVE-2026-57089 | Windows SMB Server Network Transport Driver (srvnet.sys) | Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution | Important | 7.5 |
CVE-2026-57108 | .NET Core | .NET Denial of Service | Important | 7.5 |
CVE-2026-58531 | Windows SMB | Windows SMB Elevation of Privilege | Important | 7.5 |
CVE-2026-58627 | Windows DHCP Server | Windows DHCP Server Denial of Service | Important | 7.5 |
CVE-2026-49789 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.3 |
CVE-2026-49790 | Windows Universal Disk Format File System Driver (UDFS) | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege | Important | 7.3 |
CVE-2026-50364 | Windows Server Backup | Windows Backup Service Elevation of Privilege | Important | 7.3 |
CVE-2026-50482 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.3 |
CVE-2026-55021 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 7.3 |
CVE-2026-55034 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 7.3 |
CVE-2026-55126 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 7.3 |
CVE-2026-58640 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.3 |
CVE-2026-49165 | Microsoft Windows App Store | Microsoft Windows App Store Information Disclosure | Important | 7.1 |
CVE-2026-49791 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege | Important | 7.1 |
CVE-2026-50354 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.1 |
CVE-2026-50428 | Windows Container Isolation FS Filter Driver (unionfs.sys) | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure | Important | 7.1 |
CVE-2026-50451 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege | Important | 7.1 |
CVE-2026-50465 | Windows DNS | Windows DNS Client Tampering | Important | 7.1 |
CVE-2026-50682 | Windows Active Directory | Active Directory Denial of Service | Important | 7.1 |
CVE-2026-55122 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 7.1 |
CVE-2026-55144 | Windows CryptoAPI | Windows Cryptography API: Next Generation (CNG) Tampering | Important | 7.1 |
CVE-2026-56193 | Microsoft Office | Microsoft Office Information Disclosure | Important | 7.1 |
CVE-2026-57101 | Visual Studio Code | Visual Studio Code Security Feature Bypass | Important | 7.1 |
CVE-2026-58529 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services (ADFS) Information Disclosure | Important | 7.1 |
CVE-2026-48571 | Windows App Installer | Windows App Package Installer Elevation of Privilege | Important | 7.0 |
CVE-2026-48572 | Windows App Installer | Windows App Package Installer Elevation of Privilege | Important | 7.0 |
CVE-2026-49162 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.0 |
CVE-2026-49183 | Windows Clipboard Server | Windows Clipboard Server Elevation of Privilege | Important | 7.0 |
CVE-2026-49784 | Microsoft Windows App Store | Microsoft Windows App Store Elevation of Privilege | Important | 7.0 |
CVE-2026-49802 | Windows USB Print Driver | Windows USB Print Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-49803 | Windows AppX Deployment Service | Windows AppX Deployment Extensions Elevation of Privilege | Important | 7.0 |
CVE-2026-49805 | Windows Win32K | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-49806 | Windows USB Print Driver | Windows USB Print Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-50296 | Windows Graphics Kernel | DirectX Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-50297 | Windows Win32K | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-50307 | Windows TCP/IP | Windows TCP/IP Elevation of Privilege | Important | 7.0 |
CVE-2026-50322 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50323 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50325 | Windows Win32K | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-50345 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50348 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50356 | Microsoft Windows App Store | Microsoft Windows App Store Elevation of Privilege | Important | 7.0 |
CVE-2026-50358 | Windows Media | Windows Media Elevation of Privilege | Important | 7.0 |
CVE-2026-50359 | Microsoft XML Core Services | Microsoft XML Core Services Elevation of Privilege | Important | 7.0 |
CVE-2026-50371 | Windows LUAFV | Windows LUA File Virtualization Filter Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-50372 | Windows Redirected Drive Buffering | Windows Redirected Drive Buffering System Elevation of Privilege | Important | 7.0 |
CVE-2026-50384 | Windows Clip Service | Windows Clip Service Elevation of Privilege | Important | 7.0 |
CVE-2026-50390 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-50393 | Windows Kernel-Mode Drivers | Windows Kernel-Mode Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-50396 | Windows Kernel-Mode Drivers | Windows Kernel-Mode Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-50397 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-50403 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50404 | Windows Media | Windows Media Elevation of Privilege | Important | 7.0 |
CVE-2026-50406 | Windows Backup Engine | Windows Backup Engine Elevation of Privilege | Important | 7.0 |
CVE-2026-50410 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50449 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50452 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50459 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-50490 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.0 |
CVE-2026-50491 | Code Integrity DLL (ci.dll) | Code Integrity DLL (ci.dll) Elevation of Privilege | Important | 7.0 |
CVE-2026-50503 | Windows Runtime | Windows Runtime Elevation of Privilege | Important | 7.0 |
CVE-2026-50526 | .NET | .NET Tampering | Important | 7.0 |
CVE-2026-50658 | Microsoft Defender | Microsoft Defender for Endpoint for Mac Elevation of Privilege | Important | 7.0 |
CVE-2026-50669 | Windows Telephony Service | Windows Telephony Server Elevation of Privilege | Important | 7.0 |
CVE-2026-50672 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.0 |
CVE-2026-50674 | Windows USB Print Driver | Windows USB Print Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-54111 | Windows USB Print Driver | Universal Print Management Service Elevation of Privilege | Important | 7.0 |
CVE-2026-54129 | Windows Hyper-V | Windows Hyper-V Elevation of Privilege | Important | 7.0 |
CVE-2026-54989 | Quality Windows Audio/Video Experience (QWAVE) service | Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege | Important | 7.0 |
CVE-2026-54996 | Windows USB Print Driver | Windows USB Print Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-56173 | Windows WebView | Windows WebView Elevation of Privilege | Important | 7.0 |
CVE-2026-56183 | Windows MIDI Service Module | Windows MIDI Service Module Elevation of Privileges | Important | 7.0 |
CVE-2026-56187 | Windows MIDI Service Module | Windows MIDI Service Module Elevation of Privileges | Important | 7.0 |
CVE-2026-57093 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-58526 | Windows Storage | Windows Storage Elevation of Privilege | Important | 7.0 |
CVE-2026-58544 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.0 |
CVE-2026-58619 | Windows Sensor Data Service | Windows Sensor Data Service Elevation of Privilege | Important | 7.0 |
CVE-2026-58629 | Windows DirectX | DirectX Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-58637 | Windows Client-Side Caching (CSC) Service | Windows Client-Side Caching Elevation of Privilege | Important | 7.0 |
CVE-2026-49168 | Windows Storage Spaces Direct | Storage Spaces Direct Elevation of Privilege | Important | 6.8 |
CVE-2026-50298 | Windows Spaceport.sys | Windows Spaceport.sys Elevation of Privilege | Important | 6.8 |
CVE-2026-50299 | Windows Storage Spaces Direct | Windows Storage Spaces Direct Remote Code Execution | Important | 6.8 |
CVE-2026-50426 | Role: DNS Server | Windows DNS Server Remote Code Execution | Important | 6.8 |
CVE-2026-50492 | Windows Resilient File System (ReFS) | Windows Resilient File System (ReFS) Remote Code Execution | Important | 6.8 |
CVE-2026-50668 | Windows NTFS | Windows Resilient File System (ReFS) Elevation of Privilege | Important | 6.8 |
CVE-2026-54132 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 6.8 |
CVE-2026-58528 | Windows USB Audio Class driver (usbaudio.sys) | Windows USB Audio Class Driver Information Disclosure | Important | 6.8 |
CVE-2026-49804 | Windows USB Video Driver | Windows USB Video Driver Elevation of Privilege | Important | 6.6 |
CVE-2026-50678 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 6.6 |
CVE-2026-34348 | Windows Event Logging Service | Windows Event Logging Service Information Disclosure | Important | 6.5 |
CVE-2026-47282 | GitHub Copilot and Visual Studio Code | GitHub Copilot and Visual Studio Code Information Disclosure | Important | 6.5 |
CVE-2026-49799 | Windows Local Security Authority Subsystem Service (LSASS) | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service | Important | 6.5 |
CVE-2026-50366 | Active Directory Domain Services | Windows Active Directory Domain Services Denial of Service | Important | 6.5 |
CVE-2026-50376 | Windows RDP | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-50445 | Windows RDP | Windows Remote Desktop Protocol (RDP) Information Disclosure | Important | 6.5 |
CVE-2026-50468 | SQL Server | Microsoft SQL Server Information Disclosure | Important | 6.5 |
CVE-2026-50497 | Windows Remote Desktop Protocol | Windows Remote Desktop Protocol (RDP) Information Disclosure | Important | 6.5 |
CVE-2026-50504 | Remote Desktop Client | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-50659 | .NET | .NET Spoofing | Important | 6.5 |
CVE-2026-54108 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 6.5 |
CVE-2026-54116 | SQL Server | Microsoft SQL Server Information Disclosure | Important | 6.5 |
CVE-2026-54126 | Windows RDP | Windows Remote Desktop Protocol (RDP) Information Disclosure | Important | 6.5 |
CVE-2026-55003 | Windows RDP | Windows Remote Desktop Protocol (RDP) Information Disclosure | Important | 6.5 |
CVE-2026-55051 | Microsoft Office SharePoint | Microsoft SharePoint Server Information Disclosure | Important | 6.5 |
CVE-2026-55054 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 6.5 |
CVE-2026-56168 | Windows SMB Server | Windows SMB Server Denial of Service | Important | 6.5 |
CVE-2026-56185 | Windows Admin Center | Windows Admin Center Information Disclosure | Important | 6.5 |
CVE-2026-57976 | Active Directory Domain Services | Windows Active Directory Domain Services Denial of Service | Important | 6.5 |
CVE-2026-57979 | Windows RDP | Windows Remote Desktop Protocol (RDP) Information Disclosure | Important | 6.5 |
CVE-2026-57982 | Windows RDP | Windows Remote Desktop Protocol (RDP) Information Disclosure | Important | 6.5 |
CVE-2026-58279 | Azure CycleCloud | Azure CycleCloud Elevation of Privilege | Important | 6.5 |
CVE-2026-58533 | Windows RDP | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-58535 | Windows RDP | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-58539 | Windows RDP | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-58546 | Windows RDP | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-55000 | Windows USB Print Driver | Windows USB Print Driver Elevation of Privilege | Important | 6.4 |
CVE-2026-57097 | Microsoft XML | Microsoft XML Security Feature Bypass | Important | 6.4 |
CVE-2026-50374 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 6.3 |
CVE-2026-50375 | Windows DirectX | DirectX Graphics Kernel Elevation of Privilege | Important | 6.3 |
CVE-2026-57973 | Windows Subsystem for Linux | Windows Subsystem for Linux (WSL2) Kernel Tampering | Important | 6.3 |
CVE-2026-58543 | Windows USB Print Driver | Universal Print Management Service Elevation of Privilege | Important | 6.3 |
CVE-2026-49807 | Windows DirectX | Windows DirectX Information Disclosure | Important | 6.2 |
CVE-2026-50294 | Windows Kernel | Windows Kernel Information Disclosure | Important | 6.2 |
CVE-2026-50420 | Windows HTTP.sys | HTTP.sys Information Disclosure | Important | 6.2 |
CVE-2026-55026 | Microsoft Office | Microsoft Office Information Disclosure | Important | 6.2 |
CVE-2026-57095 | Windows Win32K | Win32k Elevation of Privilege | Important | 6.2 |
CVE-2026-49174 | Windows DNS | DNS Client Tampering | Important | 6.1 |
CVE-2026-50383 | Windows Print Spooler Components | Windows Print Spooler Information Disclosure | Important | 6.1 |
CVE-2026-50453 | Windows USB Audio Class driver (usbaudio.sys) | Windows USB Audio Class Driver Information Disclosure | Important | 6.1 |
CVE-2026-50495 | Windows DNS | DNS Client Tampering | Important | 6.1 |
CVE-2026-50661 | Windows BitLocker | Windows BitLocker Security Feature Bypass | Important | 6.1 |
CVE-2026-54988 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 6.1 |
CVE-2026-55898 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 6.1 |
CVE-2026-58638 | Windows Boot Loader | Windows Boot Loader Security Feature Bypass | Important | 6.0 |
CVE-2026-50324 | Active Directory Federation Services (AD FS) | Windows Active Directory Federation Services Denial of Service | Important | 5.9 |
CVE-2026-56649 | Windows Network File System | Windows Network File System Remote Code Execution | Important | 5.9 |
CVE-2026-33842 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-34328 | Windows Audio Service | Windows Audio Service Information Disclosure | Important | 5.5 |
CVE-2026-34346 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Information Disclosure | Important | 5.5 |
CVE-2026-34349 | Windows Media | Windows Media Information Disclosure | Important | 5.5 |
CVE-2026-40422 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-41087 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-45496 | Visual Studio Code | Visual Studio Code Security Feature Bypass | Important | 5.5 |
CVE-2026-48580 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-49177 | Windows TCP/IP | Windows TCP/IP Information Disclosure | Important | 5.5 |
CVE-2026-49180 | Universal Plug and Play (upnp.dll) | Universal Plug and Play (upnp.dll) Information Disclosure | Important | 5.5 |
CVE-2026-49801 | Windows SMB | Windows SMB Information Disclosure | Important | 5.5 |
CVE-2026-50295 | Windows DNS | Windows Zero Trust DNS Security Feature Bypass | Important | 5.5 |
CVE-2026-50300 | Windows Kernel | Windows DWM Core Library Information Disclosure | Important | 5.5 |
CVE-2026-50303 | Windows Key Guard | Windows Key Guard Security Feature Bypass | Important | 5.5 |
CVE-2026-50316 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2026-50334 | Windows Notification | Windows Push Notification Information Disclosure | Important | 5.5 |
CVE-2026-50339 | Windows Push Notifications | Windows Push Notification Information Disclosure | Important | 5.5 |
CVE-2026-50341 | Windows NTFS | Windows NTFS Information Disclosure | Important | 5.5 |
CVE-2026-50350 | Windows Trusted Runtime Interface Driver | Windows Trusted Runtime Interface Driver Information Disclosure | Important | 5.5 |
CVE-2026-50352 | Windows Cryptographic Services | Windows Cryptographic Services Information Disclosure | Important | 5.5 |
CVE-2026-50377 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 5.5 |
CVE-2026-50381 | Composite Image File System Driver | Composite Image File System driver (cimfs.sys) Information Disclosure | Important | 5.5 |
CVE-2026-50389 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-50394 | Windows Media | Windows Media Information Disclosure | Important | 5.5 |
CVE-2026-50401 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Information Disclosure | Important | 5.5 |
CVE-2026-50408 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-50409 | Windows Overlay Filter | Windows Overlay Filter Information Disclosure | Important | 5.5 |
CVE-2026-50430 | Windows Push Notifications | Windows Push Notification Information Disclosure | Important | 5.5 |
CVE-2026-50431 | Windows Quality of Service (QoS) Packet Scheduler | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure | Important | 5.5 |
CVE-2026-50434 | Windows Push Notifications | Windows Push Notification Information Disclosure | Important | 5.5 |
CVE-2026-50437 | Windows DWM Core Library | Windows DWM Core Library Information Disclosure | Important | 5.5 |
CVE-2026-50442 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-50455 | Universal Plug and Play (upnp.dll) | Universal Plug and Play (upnp.dll) Information Disclosure | Important | 5.5 |
CVE-2026-50456 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-50473 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-50475 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2026-50483 | Microsoft Graphics Component | Windows Graphics Component Information Disclosure | Important | 5.5 |
CVE-2026-50681 | Windows Cryptographic Services | Windows Secure Channel Information Disclosure | Important | 5.5 |
CVE-2026-50690 | Windows SMB | Windows SMB Information Disclosure | Important | 5.5 |
CVE-2026-54997 | Windows SMB | Windows SMB Information Disclosure | Important | 5.5 |
CVE-2026-55023 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55027 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55028 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55035 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55042 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55046 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-55047 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55050 | Microsoft Office Word | Microsoft Word Information Disclosure | Important | 5.5 |
CVE-2026-55057 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55121 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55124 | Microsoft Office Word | Microsoft Word Information Disclosure | Important | 5.5 |
CVE-2026-55138 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-55139 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-55142 | Microsoft Office Word | Microsoft Word Information Disclosure | Important | 5.5 |
CVE-2026-56178 | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint for Mac Elevation of Privilege | Important | 5.5 |
CVE-2026-56184 | Windows Win32K | Win32k Information Disclosure | Important | 5.5 |
CVE-2026-56192 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-56195 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-57083 | Microsoft Windows Codecs Library | Windows Media Photo Codec Information Disclosure | Important | 5.5 |
CVE-2026-57084 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-57085 | Windows Print Spooler Components | Windows Print Spooler Information Disclosure | Important | 5.5 |
CVE-2026-58545 | Windows Kernel | Windows Kernel Security Feature Bypass | Important | 5.5 |
CVE-2026-58547 | Universal Plug and Play (upnp.dll) | Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege | Important | 5.5 |
CVE-2026-58614 | Windows Kernel | Windows Kernel Security Feature Bypass | Important | 5.5 |
CVE-2026-56157 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 5.4 |
CVE-2026-44806 | Windows Cryptographic Services | Windows Secure Channel Denial of Service | Important | 5.3 |
CVE-2026-50415 | Windows Media | Windows Media Information Disclosure | Important | 5.3 |
CVE-2026-50432 | Windows Virtual Filtering Platform (VFP) | Window Virtual Filtering Platform (VFP) Denial of Service | Important | 5.3 |
CVE-2026-50418 | Windows System | Windows System Secure Feature Bypass | Important | 5.1 |
CVE-2026-50684 | Active Directory Federation Services (AD FS) | Active Directory Federation Server Spoofing | Important | 4.8 |
CVE-2026-49167 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 4.7 |
CVE-2026-50310 | Windows Devices Human Interface | Windows Human Interface Device Information Disclosure | Important | 4.7 |
CVE-2026-50312 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 4.7 |
CVE-2026-50657 | Microsoft Defender | Microsoft Defender for Endpoint for Mac Information Disclosure | Important | 4.7 |
CVE-2026-49794 | Windows USB Audio Class driver (usbaudio.sys) | Windows USB Audio Class Driver Information Disclosure | Important | 4.6 |
CVE-2026-55016 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-55019 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-55020 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-55030 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-55135 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-50485 | Windows Hyper-V | Windows Hyper-V Denial of Service | Important | 4.5 |
CVE-2026-50302 | Windows Cryptographic Services | Windows Cryptographic Services Security Feature Bypass | Important | 4.2 |
CVE-2026-50416 | Windows Win32K | Win32k Information Disclosure | Important | 3.3 |
CVE-2026-50419 | Windows Kernel | Windows Kernel Information Disclosure | Important | 3.3 |
CVE-2026-56181 | Windows Network Address Translation (NAT) | Windows Network Address Translation (NAT) Spoofing | Moderate | 8.3 |
CVE-2026-55145 | Outlook Copilot | Outlook Copilot Tampering | Moderate | 6.3 |
CVE-2026-56164 | Microsoft Office SharePoint | Microsoft SharePoint Server Elevation of Privilege | Moderate | 5.3 |
Published later in the month (92)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 23 Jul | CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-56191 | Microsoft Exchange Online Tampering | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-57106 | Data Quality Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-58275 | Azure DNS Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-62825 | Azure Key Vault Elevation of Privilege | Critical | Fixed by Microsoft |
| 30 Jul | CVE-2026-66803 | Azure Cosmos DB Remote Code Execution | Critical | Fixed by Microsoft |
| 2 Jul | CVE-2026-45499 | Azure OpenAI Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-50517 | Microsoft M365 Copilot Remote Code Execution | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-54120 | Microsoft Surface Remote Code Execution | Critical | Fixed by Microsoft |
| 2 Jul | CVE-2026-57100 | Microsoft Entra Provisioning Service Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-56165 | Microsoft Account Remote Code Execution | Critical | Fixed by Microsoft |
| 2 Jul | CVE-2026-41106 | Microsoft 365 Copilot Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-62835 | Azure Portal Information Disclosure | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-56160 | Azure Red Hat OpenShift (ARO) Elevation of Privilege | Critical | Fixed by Microsoft |
| 2 Jul | CVE-2026-54998 | Microsoft Exchange Online Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-56167 | Azure AI Search Elevation of Privilege | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-35425 | Azure API Management (APIM) Remote Code Execution | Critical | Fixed by Microsoft |
| 23 Jul | CVE-2026-49159 | Microsoft Graph Information Disclosure | Critical | Fixed by Microsoft |
| 2 Jul | CVE-2026-26145 | Microsoft Azure Synapse Elevation of Privilege | Critical | Fixed by Microsoft |
| 3 Jul | CVE-2026-58289 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-56645 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-57974 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-57981 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 31 Jul | CVE-2026-62870 | Microsoft Excel Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-57983 | Microsoft Edge (Chromium-based) Security Feature Bypass | Important | Update |
| 11 Jul | CVE-2026-58281 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58284 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58285 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58287 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58288 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58295 | Microsoft Edge (Chromium-based) Security Feature Bypass | Important | Update |
| 11 Jul | CVE-2026-58596 | Microsoft Edge (Chromium-based) Elevation of Privilege | Important | Update |
| 8 Jul | CVE-2026-58525 | Microsoft Edge (Chromium-based) Security Feature Bypass | Important | Update |
| 3 Jul | CVE-2026-58282 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 3 Jul | CVE-2026-58283 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 3 Jul | CVE-2026-58286 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 3 Jul | CVE-2026-58293 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 31 Jul | CVE-2026-66318 | Microsoft Edge (Chromium-based) Information Disclosure | Important | Update |
| 31 Jul | CVE-2026-66310 | Microsoft Edge for Android Information Disclosure | Important | Update |
| 3 Jul | CVE-2026-57985 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-57975 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-57984 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-57986 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-57992 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58276 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58290 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58292 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58294 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58299 | Microsoft Edge for Android Remote Code Execution | Important | Update |
| 16 Jul | CVE-2026-59117 | Windows Terminal Remote Code Execution | Important | Update |
| 31 Jul | CVE-2026-66315 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 24 Jul | CVE-2026-57989 | Microsoft Edge (Chromium-based) Information Disclosure | Important | Update |
| 24 Jul | CVE-2026-57990 | Microsoft Edge (Chromium-based) Information Disclosure | Important | Update |
| 2 Jul | CVE-2026-57991 | Microsoft Edge (Chromium-based) Information Disclosure | Important | Update |
| 3 Jul | CVE-2026-57993 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 31 Jul | CVE-2026-65802 | Microsoft Edge for Android Information Disclosure | Important | Update |
| 31 Jul | CVE-2026-66321 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58298 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 16 Jul | CVE-2026-56171 | Windows Remote Desktop Protocol (RDP) Information Disclosure | Important | Update |
| 3 Jul | CVE-2026-57977 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 3 Jul | CVE-2026-57988 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58296 | Microsoft Edge for Android Information Disclosure | Important | Update |
| 3 Jul | CVE-2026-58297 | Microsoft Edge for Android Information Disclosure | Important | Update |
| 31 Jul | CVE-2026-66322 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 16 Jul | CVE-2026-58598 | Windows Backup Service Elevation of Privilege | Important | Update |
| 3 Jul | CVE-2026-58522 | Microsoft Edge for Android Information Disclosure | Important | Update |
| 31 Jul | CVE-2026-66313 | Microsoft Edge (Chromium-based) Tampering | Important | Update |
| 3 Jul | CVE-2026-56646 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 3 Jul | CVE-2026-57987 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 3 Jul | CVE-2026-58523 | Microsoft Edge for Android Security Feature Bypass | Important | Update |
| 31 Jul | CVE-2026-66312 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 31 Jul | CVE-2026-66314 | Microsoft Edge (Chromium-based) Information Disclosure | Important | Update |
| 31 Jul | CVE-2026-66326 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 3 Jul | CVE-2026-58300 | Microsoft Edge for Android Information Disclosure | Important | Update |
| 31 Jul | CVE-2026-66311 | Microsoft Edge (Chromium-based) Tampering | Important | Update |
| 3 Jul | CVE-2026-58291 | Microsoft Edge (Chromium-based) Information Disclosure | Important | Update |
| 16 Jul | CVE-2026-58643 | Windows Admin Center Spoofing | Important | Update |
| 31 Jul | CVE-2026-65804 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 31 Jul | CVE-2026-66325 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 24 Jul | CVE-2026-57978 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 16 Jul | CVE-2026-57980 | Microsoft Edge (Chromium-based) Tampering | Important | Update |
| 3 Jul | CVE-2026-58278 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 3 Jul | CVE-2026-58524 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 31 Jul | CVE-2026-66316 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 31 Jul | CVE-2026-66317 | Microsoft Edge (Chromium-based) Tampering | Important | Update |
| 16 Jul | CVE-2026-62826 | Microsoft SharePoint Server Spoofing | Important | Update |
| 3 Jul | CVE-2026-45489 | Microsoft Edge (Chromium-based) Spoofing | Moderate | Update |
| 3 Jul | CVE-2026-45488 | Microsoft Edge (Chromium-based) Spoofing | Moderate | Update |
| 16 Jul | CVE-2026-62828 | Microsoft Edge for Android (Chromium-based) Tampering | Moderate | Update |
| 3 Jul | CVE-2026-55945 | Microsoft Edge (Chromium-based) Information Disclosure | Moderate | Update |
| 3 Jul | CVE-2026-58597 | Microsoft Edge (Chromium-based) Spoofing | Low | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 21 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.