How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
August 2026 Patch Tuesday: Microsoft fixed 402 vulnerabilities, 44 of them Critical. 1 was already being exploited. Released Tue 11 Aug 2026.
- 402vulnerabilities fixed
- 44Critical
- 1exploited before the fix
- 2publicly disclosed
- 2now on CISA KEV
By type: 163 elevation of privilege, 112 remote code execution, 85 information disclosure, 16 spoofing, 11 security feature bypass, 11 denial of service, 4 tampering.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2026-65660 | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 | On CISA KEV federal deadline 28 Sep |
CVE-2026-62832 | Windows User Profile Service Elevation of Privilege | Important | 7.8 | Publicly disclosed |
CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 | Exploited On CISA KEV federal deadline 25 Aug |
CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering | Important | 5.5 | Publicly disclosed |
Critical (44)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2026-62815 | Microsoft QUIC Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-62878 | Windows DNS Server Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-65791 | Windows iSCSI Target Service Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-62816 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-62817 | Windows DNS Server Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-62818 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-62822 | Windows GDI+ Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-62823 | Windows DHCP Server Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-62824 | Remote Desktop Client Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-62827 | Microsoft SharePoint Server Elevation of Privilege | Elevation of Privilege | 8.8 |
CVE-2026-64921 | Microsoft SharePoint Server Elevation of Privilege | Elevation of Privilege | 8.8 |
CVE-2026-65665 | Microsoft SharePoint Server Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-70130 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-62819 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-62820 | Windows DNS Server Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-62889 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-65679 | Windows iSCSI Target Service Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-65789 | Windows DNS Server Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-65796 | Windows iSCSI Target Service Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-66802 | Windows Device Health Attestation (DHA) Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-71331 | Windows Device Health Attestation (DHA) Remote Code Execution | Remote Code Execution | 8.1 |
CVE-2026-62911 | Microsoft Exchange Server Elevation of Privilege | Elevation of Privilege | 8.0 |
CVE-2026-62890 | Windows GDI+ Elevation of Privilege | Remote Code Execution | 7.8 |
CVE-2026-63513 | Microsoft Office Graphics Component Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-63515 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-63518 | Microsoft Office Word Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-63519 | Microsoft Office Graphics Component Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-63525 | Microsoft Office Word Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-63526 | Microsoft Office Graphics Component Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-63532 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-64898 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-64903 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-64907 | Microsoft Office Word Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-64909 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-64910 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-64911 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-65657 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-65664 | Microsoft Office Graphics Component Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-66799 | Windows Key Guard Elevation of Privilege | Elevation of Privilege | 7.8 |
CVE-2026-66807 | Microsoft Office Graphics Component Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-68794 | Microsoft Excel Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-68804 | Microsoft Excel Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-68816 | Microsoft Excel Remote Code Execution | Remote Code Execution | 7.8 |
Added to CISA KEV in August 2026 (31)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2026-81578 | PaperCut NG/MF | Missing Authentication for Critical Function | 31 Aug | 14 Sep 2026 | |
CVE-2026-82078 | PaperCut NG/MF | Unsafe Reflection | 31 Aug | 14 Sep 2026 | |
CVE-2023-49105 | ownCloud ownCloud | ownCloud Improper Authentication | 27 Aug | 30 Aug 2026 | |
CVE-2026-53362 | Linux Kernel | Unspecified | 27 Aug | 30 Aug 2026 | |
CVE-2026-66384 | JFrog Artifactory | Improper Limitation of a Pathname to a Restricted Directory | 27 Aug | 10 Sep 2026 | |
CVE-2015-3246 | Red Hat Libuser | Race Condition | 26 Aug | 9 Sep 2026 | |
CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | Privilege Escalation | 26 Aug | 9 Sep 2026 | |
CVE-2019-1068 | Microsoft SQL Server | Remote Code Execution | 26 Aug | 29 Aug 2026 | |
CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional | Ajax.NET Professional Deserialization of Untrusted Data | 26 Aug | 9 Sep 2026 | |
CVE-2022-0995 | Linux Kernel | Out-of-Bounds Write | 26 Aug | 29 Aug 2026 | |
CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway | Improper Restriction of Operations within the Bounds of a Memory Buffer | 26 Aug | 29 Aug 2026 | |
CVE-2026-60004 | Gitea Gitea | Gitea Code Injection | 25 Aug | 28 Aug 2026 | |
CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Improper Access Control | 24 Aug | 27 Aug 2026 | |
CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | Zimbra Collaboration Suite (ZCS) OS Command Injection | 21 Aug | 24 Aug 2026 | |
CVE-2026-72529 | TrueConf Server | Missing Authentication for Critical Function | 20 Aug | 23 Aug 2026 | |
CVE-2026-72530 | TrueConf Server | Code Injection | 20 Aug | 3 Sep 2026 | |
CVE-2026-64849 | MLflow MLflow | MLflow Server-Side Request Forgery | 19 Aug | 2 Sep 2026 | |
CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Double Free | 18 Aug | 21 Aug 2026 | |
CVE-2026-55040 | Microsoft SharePoint | Weak Authentication | 18 Aug | 21 Aug 2026 | |
CVE-2026-59310 | Broadcom VMware vCenter | Path Traversal | 18 Aug | 21 Aug 2026 | Known |
CVE-2026-65400 | Apple macOS | Improper Authentication | 18 Aug | 21 Aug 2026 | |
CVE-2025-62593 | Ray-Project Ray | Code Injection | 17 Aug | 20 Aug 2026 | |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection | 11 Aug | 14 Aug 2026 | |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free | 11 Aug | 25 Aug 2026 | |
CVE-2026-72898 | Metabase Metabase | Metabase SQL Injection | 11 Aug | 14 Aug 2026 | |
CVE-2026-8037 | Progress LoadMaster | Command Injection | 7 Aug | 10 Aug 2026 | |
CVE-2026-63077 | JetBrains TeamCity | Deserialization of Untrusted Data | 5 Aug | 8 Aug 2026 | Known |
CVE-2026-18556 | N-able N-central | Authentication Bypass Using an Alternate Path or Channel | 4 Aug | 7 Aug 2026 | |
CVE-2026-34486 | Apache Tomcat | Missing Encryption of Sensitive Data | 4 Aug | 7 Aug 2026 | |
CVE-2026-9198 | IBM Langflow | Code Injection | 4 Aug | 7 Aug 2026 | |
CVE-2026-18577 | N-able N-central | Authentication Bypass Using an Alternate Path or Channel | 3 Aug | 6 Aug 2026 |
All 402 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2026-62815 | Microsoft QUIC | Microsoft QUIC Remote Code Execution | Critical | 9.8 |
CVE-2026-62878 | Windows DNS | Windows DNS Server Remote Code Execution | Critical | 9.8 |
CVE-2026-62893 | Windows Deployment Services | Windows Deployment Services TFTP Server Remote Code Execution | Critical | 9.8 |
CVE-2026-65791 | Windows iSCSI Target Service | Windows iSCSI Target Service Remote Code Execution | Critical | 9.8 |
CVE-2026-62816 | Reliable Multicast Transport Driver (RMCAST) | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution | Critical | 8.8 |
CVE-2026-62817 | Windows DNS | Windows DNS Server Remote Code Execution | Critical | 8.8 |
CVE-2026-62818 | Active Directory Certificate Services (AD CS) | Windows Active Directory Certificate Services (AD CS) Remote Code Execution | Critical | 8.8 |
CVE-2026-62822 | Windows GDI+ | Windows GDI+ Remote Code Execution | Critical | 8.8 |
CVE-2026-62823 | Windows DHCP Server | Windows DHCP Server Remote Code Execution | Critical | 8.8 |
CVE-2026-62824 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Critical | 8.8 |
CVE-2026-62827 | Microsoft Office SharePoint | Microsoft SharePoint Server Elevation of Privilege | Critical | 8.8 |
CVE-2026-64921 | Microsoft Office SharePoint | Microsoft SharePoint Server Elevation of Privilege | Critical | 8.8 |
CVE-2026-65665 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Critical | 8.8 |
CVE-2026-70130 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-62819 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Critical | 8.1 |
CVE-2026-62820 | Windows DNS | Windows DNS Server Remote Code Execution | Critical | 8.1 |
CVE-2026-62889 | Windows Secure Socket Tunneling Protocol (SSTP) | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution | Critical | 8.1 |
CVE-2026-65679 | Windows iSCSI Target Service | Windows iSCSI Target Service Remote Code Execution | Critical | 8.1 |
CVE-2026-65789 | Windows DNS | Windows DNS Server Remote Code Execution | Critical | 8.1 |
CVE-2026-65796 | Windows iSCSI Target Service | Windows iSCSI Target Service Remote Code Execution | Critical | 8.1 |
CVE-2026-66802 | Windows Device Health Attestation (DHA) | Windows Device Health Attestation (DHA) Remote Code Execution | Critical | 8.1 |
CVE-2026-71331 | Windows Device Health Attestation (DHA) | Windows Device Health Attestation (DHA) Remote Code Execution | Critical | 8.1 |
CVE-2026-62911 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Critical | 8.0 |
CVE-2026-62890 | Windows GDI+ | Windows GDI+ Elevation of Privilege | Critical | 7.8 |
CVE-2026-63513 | Microsoft Office | Microsoft Office Graphics Component Remote Code Execution | Critical | 7.8 |
CVE-2026-63515 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-63518 | Microsoft Office Word | Microsoft Office Word Remote Code Execution | Critical | 7.8 |
CVE-2026-63519 | Microsoft Office | Microsoft Office Graphics Component Remote Code Execution | Critical | 7.8 |
CVE-2026-63525 | Microsoft Office Word | Microsoft Office Word Remote Code Execution | Critical | 7.8 |
CVE-2026-63526 | Microsoft Office | Microsoft Office Graphics Component Remote Code Execution | Critical | 7.8 |
CVE-2026-63532 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-64898 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-64903 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-64907 | Microsoft Office Word | Microsoft Office Word Remote Code Execution | Critical | 7.8 |
CVE-2026-64909 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-64910 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-64911 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-65657 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-65664 | Microsoft Office | Microsoft Office Graphics Component Remote Code Execution | Critical | 7.8 |
CVE-2026-66799 | Windows Key Guard | Windows Key Guard Elevation of Privilege | Critical | 7.8 |
CVE-2026-66807 | Microsoft Office | Microsoft Office Graphics Component Remote Code Execution | Critical | 7.8 |
CVE-2026-68794 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Critical | 7.8 |
CVE-2026-68804 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Critical | 7.8 |
CVE-2026-68816 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Critical | 7.8 |
CVE-2026-59124 | Microsoft High Performance Computing (HPC) Pack | Microsoft High Performance Computing (HPC) Pack Remote Code Execution | Important | 9.8 |
CVE-2026-70306 | Microsoft Office SharePoint | Microsoft Office SharePoint Spoofing | Important | 9.3 |
CVE-2026-49179 | Windows Active Directory | Windows Active Directory Domain Services Remote Code Execution | Important | 8.8 |
CVE-2026-57104 | Azure Storage Explorer | Azure Storage Explorer Elevation of Privilege | Important | 8.8 |
CVE-2026-59113 | Visual Studio Code | Visual Studio Code Remote Code Execution | Important | 8.8 |
CVE-2026-59133 | Microsoft High Performance Computing (HPC) Pack | Microsoft High Performance Computing (HPC) Pack Elevation of Privilege | Important | 8.8 |
CVE-2026-62784 | Microsoft Local Security Authority Server (lsasrv) | Microsoft Local Security Authority Server (lsasrv) Remote Code Execution | Important | 8.8 |
CVE-2026-62785 | Windows LDAP – Lightweight Directory Access Protocol | Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution | Important | 8.8 |
CVE-2026-62790 | Windows SMB Server | Windows SMBv3 Server Remote Code Execution | Important | 8.8 |
CVE-2026-62795 | Windows LDAP – Lightweight Directory Access Protocol | Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution | Important | 8.8 |
CVE-2026-62800 | Windows SMB Server | Windows SMBv3 Server Remote Code Execution | Important | 8.8 |
CVE-2026-62872 | .NET Framework | .NET Framework Elevation of Privilege | Important | 8.8 |
CVE-2026-62913 | Microsoft Exchange Server | Microsoft Exchange Server Remote Code Execution | Important | 8.8 |
CVE-2026-63514 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-64901 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-65658 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-65660 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-65663 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-65767 | Microsoft Teams for Android | Microsoft Teams for Android Spoofing | Important | 8.8 |
CVE-2026-65768 | Microsoft Teams for Android | Microsoft Teams Remote Code Execution | Important | 8.8 |
CVE-2026-65807 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 8.8 |
CVE-2026-65811 | Power BI | Power BI Remote Code Execution | Important | 8.8 |
CVE-2026-65815 | Microsoft Dynamics 365 (on-premises) | Microsoft Dynamics 365 On-Premises Remote Code Execution | Important | 8.8 |
CVE-2026-66805 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-66808 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-69320 | Visual Studio Code | Visual Studio Code Remote Code Execution | Important | 8.8 |
CVE-2026-70321 | Microsoft Office SharePoint | Microsoft SharePoint Remote Code Execution | Important | 8.8 |
CVE-2026-70324 | Microsoft Office SharePoint | Microsoft SharePoint Elevation of Privilege | Important | 8.8 |
CVE-2026-70326 | Microsoft Office SharePoint | Microsoft SharePoint Server Elevation of Privilege | Important | 8.8 |
CVE-2026-70329 | Microsoft Office Outlook | Microsoft Outlook Remote Code Execution | Important | 8.8 |
CVE-2026-70336 | Visual Studio Code | Visual Studio Code Remote Code Execution | Important | 8.8 |
CVE-2026-70337 | Microsoft PowerShell Core | Microsoft PowerShell Remote Code Execution | Important | 8.8 |
CVE-2026-69306 | Visual Studio Code | Visual Studio Code Security Feature Bypass | Important | 8.2 |
CVE-2026-62778 | Windows DNS | Windows DNS Elevation of Privilege | Important | 8.1 |
CVE-2026-62781 | RPC Runtime | RPC Runtime Library Remote Code Execution | Important | 8.1 |
CVE-2026-62792 | Windows TCP/IP | Windows TCP/IP Remote Code Execution | Important | 8.1 |
CVE-2026-63520 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.1 |
CVE-2026-70340 | Azure CycleCloud | Azure CycleCloud Elevation of Privilege | Important | 8.1 |
CVE-2026-57105 | Microsoft Office SharePoint | Microsoft Office SharePoint Spoofing | Important | 8.0 |
CVE-2026-42976 | Windows RPC API | Remote Access Management service/API (RPC server) Elevation of Privilege | Important | 7.8 |
CVE-2026-50523 | Microsoft PowerShell | Microsoft PowerShell Remote Code Execution | Important | 7.8 |
CVE-2026-54981 | Visual Studio Code – Python extension | Visual Studio Code Python Extension Security Feature Bypass | Important | 7.8 |
CVE-2026-54984 | Windows Imaging Component | Windows Imaging Component Remote Code Execution | Important | 7.8 |
CVE-2026-56174 | Windows Narrator Braille | Windows Narrator Braille Elevation of Privilege | Important | 7.8 |
CVE-2026-58641 | .NET | .NET Elevation of Privilege | Important | 7.8 |
CVE-2026-58650 | Visual Studio Code | Visual Studio Code Security Feature Bypass | Important | 7.8 |
CVE-2026-58651 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-59127 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-61349 | Windows Work Folder Service | Windows Work Folder Service Elevation of Privilege | Important | 7.8 |
CVE-2026-61353 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.8 |
CVE-2026-61355 | Windows Sensor Data Service | Windows Sensor Data Service Elevation of Privilege | Important | 7.8 |
CVE-2026-61356 | Windows Remote Desktop Services | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2026-61357 | Application Information Services | Application Information Services Elevation of Privilege | Important | 7.8 |
CVE-2026-61358 | Windows Accessibility Infrastructure (ATBroker.exe) | Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege | Important | 7.8 |
CVE-2026-61359 | Windows Storage | Windows Storage Elevation of Privilege | Important | 7.8 |
CVE-2026-61364 | Windows Remote Desktop Services | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2026-61365 | Windows Remote Desktop Services | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2026-61367 | Windows Remote Desktop Services | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2026-61923 | Windows Display Enhancement Service | Windows Display Enhancement Service Elevation of Privilege | Important | 7.8 |
CVE-2026-61925 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-61926 | Windows USB Driver | Windows USB Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-61930 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-61932 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-61934 | Windows Bind Filter Driver | Windows Bind Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-61937 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-62688 | Windows MIDI Service Module | Windows MIDI Service Module Elevation of Privileges | Important | 7.8 |
CVE-2026-62692 | Windows Remote Desktop Services | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2026-62695 | Windows Storage | Windows Storage Elevation of Privilege | Important | 7.8 |
CVE-2026-62696 | Windows Program Compatibility Assistant Service | Windows Program Compatibility Assistant Service Elevation of Privilege | Important | 7.8 |
CVE-2026-62698 | Microsoft Digest Authentication | Microsoft Digest Authentication Elevation of Privilege | Important | 7.8 |
CVE-2026-62700 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-62701 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.8 |
CVE-2026-62707 | Windows Modern Device Management (MDM) | Windows Modern Device Management (MDM) Elevation of Privilege | Important | 7.8 |
CVE-2026-62710 | Windows Device Association Service | Windows Device Association Service Elevation of Privilege | Important | 7.8 |
CVE-2026-62711 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-62712 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-62713 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-62717 | Windows Message Queuing | Windows Message Queuing Elevation of Privilege | Important | 7.8 |
CVE-2026-62719 | Windows Message Queuing | Windows Message Queuing Elevation of Privilege | Important | 7.8 |
CVE-2026-62721 | User-Mode Power Service (UMPS) | Windows User-Mode Power Service (UMPS) Elevation of Privilege | Important | 7.8 |
CVE-2026-62722 | Windows Brokering File System | Microsoft Brokering File System Elevation of Privilege | Important | 7.8 |
CVE-2026-62732 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.8 |
CVE-2026-62733 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-62735 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-62736 | Windows DHCP Client | Windows DHCP Client Elevation of Privilege | Important | 7.8 |
CVE-2026-62737 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-62739 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-62741 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-62747 | Windows Device Association Service | Windows Device Association Service Elevation of Privilege | Important | 7.8 |
CVE-2026-62751 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.8 |
CVE-2026-62752 | Windows Kerberos | Windows Kerberos Elevation of Privilege | Important | 7.8 |
CVE-2026-62754 | Windows Kerberos | Windows Kerberos Elevation of Privilege | Important | 7.8 |
CVE-2026-62755 | Windows DHCP Client | Windows DHCP Client Elevation of Privilege | Important | 7.8 |
CVE-2026-62758 | Windows Remote Access Connection Manager | Windows Remote Access Connection Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-62761 | Windows DHCP Server | Windows DHCP Server Elevation of Privilege | Important | 7.8 |
CVE-2026-62768 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-62770 | Windows Shell | Windows Shell Elevation of Privilege | Important | 7.8 |
CVE-2026-62771 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-62772 | Windows Container Isolation FS Filter Driver (unionfs.sys) | Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege | Important | 7.8 |
CVE-2026-62776 | Windows DHCP Server | Windows DHCP Server Elevation of Privilege | Important | 7.8 |
CVE-2026-62777 | Windows License Manager | Windows License Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-62779 | Windows Schannel | Windows Schannel Elevation of Privilege | Important | 7.8 |
CVE-2026-62783 | Windows Remote Access Connection Manager | Windows Remote Access Connection Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-62797 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-62799 | Windows SMB Client | Windows SMB Client Elevation of Privilege | Important | 7.8 |
CVE-2026-62803 | Windows DHCP Server | Windows DHCP Server Elevation of Privilege | Important | 7.8 |
CVE-2026-62807 | Windows DHCP Server | Windows DHCP Server Elevation of Privilege | Important | 7.8 |
CVE-2026-62811 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.8 |
CVE-2026-62812 | Windows DHCP Server | Windows DHCP Server Elevation of Privilege | Important | 7.8 |
CVE-2026-62832 | Windows User Profile Service | Windows User Profile Service Elevation of Privilege | Important | 7.8 |
CVE-2026-62871 | .NET | .NET Elevation of Privilege | Important | 7.8 |
CVE-2026-62876 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-62877 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-62880 | Windows NTFS | Windows NTFS Elevation of Privilege | Important | 7.8 |
CVE-2026-62885 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-62886 | .NET | .NET Elevation of Privilege | Important | 7.8 |
CVE-2026-62888 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-62894 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-62909 | .NET | .NET Elevation of Privilege | Important | 7.8 |
CVE-2026-63527 | Microsoft Office Word | Microsoft Office Word Remote Code Execution | Important | 7.8 |
CVE-2026-63533 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2026-64904 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2026-64905 | Microsoft Office Word | Microsoft Office Word Remote Code Execution | Important | 7.8 |
CVE-2026-64906 | Microsoft Office Access | Microsoft Access Remote Code Execution | Important | 7.8 |
CVE-2026-64908 | Microsoft Office Access | Microsoft Access Remote Code Execution | Important | 7.8 |
CVE-2026-64912 | Microsoft Office Access | Microsoft Access Remote Code Execution | Important | 7.8 |
CVE-2026-64914 | Microsoft Office Access | Microsoft Access Remote Code Execution | Important | 7.8 |
CVE-2026-64915 | Microsoft Office Word | Microsoft Office Word Remote Code Execution | Important | 7.8 |
CVE-2026-64919 | Microsoft Office Access | Microsoft Access Remote Code Execution | Important | 7.8 |
CVE-2026-64920 | Microsoft Office Access | Microsoft Access Remote Code Execution | Important | 7.8 |
CVE-2026-65656 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2026-65661 | Microsoft Office | Microsoft Office Remote Code Execution | Important | 7.8 |
CVE-2026-65671 | Windows Remote Access API | Remote Access API Elevation of Privilege | Important | 7.8 |
CVE-2026-65672 | Windows Remote Access API | Remote Access API Elevation of Privilege | Important | 7.8 |
CVE-2026-65673 | Microsoft Entra Connect Sync | Microsoft Entra Connect Elevation of Privilege | Important | 7.8 |
CVE-2026-65773 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-65774 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-65775 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-65786 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-65787 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-65790 | Windows Message Queuing | Windows Message Queuing Elevation of Privilege | Important | 7.8 |
CVE-2026-65810 | .NET Framework | .NET Framework Elevation of Privilege | Important | 7.8 |
CVE-2026-65814 | Windows Storage Port Driver | Microsoft Windows Storage Port Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-66804 | Windows Cross Device Service | Microsoft Windows Cross Device Service Elevation of Privilege | Important | 7.8 |
CVE-2026-68792 | Microsoft Office | Microsoft Office Elevation of Privilege | Important | 7.8 |
CVE-2026-68793 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68795 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68796 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68798 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68800 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68801 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68803 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68805 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68806 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68807 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68810 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68811 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68812 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68814 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68815 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-68817 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-69278 | Visual Studio Code | Visual Studio Code Security Feature Bypass | Important | 7.8 |
CVE-2026-70311 | Microsoft Office Word | Microsoft Office Word Remote Code Execution | Important | 7.8 |
CVE-2026-70313 | Microsoft Office PowerPoint | Microsoft PowerPoint Remote Code Execution | Important | 7.8 |
CVE-2026-70335 | GitHub Copilot and Visual Studio Code | GitHub Copilot and Visual Studio Code Elevation of Privilege | Important | 7.8 |
CVE-2026-70338 | Microsoft PowerShell | Microsoft PowerShell Security Feature Bypass | Important | 7.8 |
CVE-2026-70344 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-70345 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-70346 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-70347 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-70354 | .NET | .NET Core Remote Code Execution | Important | 7.8 |
CVE-2026-54113 | Windows Kernel | Remote Procedure Call Denial of Service | Important | 7.5 |
CVE-2026-59132 | Windows TCP/IP | Windows TCP/IP Denial of Service | Important | 7.5 |
CVE-2026-59134 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Important | 7.5 |
CVE-2026-61352 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Important | 7.5 |
CVE-2026-61363 | Remote Desktop Client | Remote Desktop Client Remote Code Execution | Important | 7.5 |
CVE-2026-62787 | Windows DNS | Windows DNS Server Remote Code Execution | Important | 7.5 |
CVE-2026-62898 | Microsoft QUIC | Microsoft QUIC Information Disclosure | Important | 7.5 |
CVE-2026-62901 | .NET | .NET Denial of Service | Important | 7.5 |
CVE-2026-65681 | Windows iSCSI Target Service | Windows iSCSI Target Service Denial of Service | Important | 7.5 |
CVE-2026-58612 | Microsoft PowerShell Core | PowerShell Information Disclosure | Important | 7.4 |
CVE-2026-59119 | Microsoft PowerShell | PowerShell Elevation of Privilege | Important | 7.3 |
CVE-2026-62914 | Microsoft Exchange Server | Microsoft Exchange Server Spoofing | Important | 7.3 |
CVE-2026-64900 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 7.3 |
CVE-2026-68821 | Windows Package Manager | Windows Package Manager Elevation of Privilege | Important | 7.3 |
CVE-2026-70355 | Microsoft Office SharePoint | Microsoft SharePoint Server Elevation of Privilege | Important | 7.3 |
CVE-2026-47299 | Azure Monitor Agent | Azure Monitor Agent Elevation of Privilege | Important | 7.2 |
CVE-2026-62910 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Important | 7.2 |
CVE-2026-65675 | Visual Studio Code CoPilot Chat Extension | CoPilot Chat Security Feature Bypass | Important | 7.1 |
CVE-2026-50472 | Windows LUAFV | Windows LUA File Virtualization Filter Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-59122 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-59125 | Virtual Hard Disk (VHD) Miniport Driver | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability | Important | 7.0 |
CVE-2026-59126 | Windows Event Logging Service | Windows Event Logging Service Elevation of Privilege | Important | 7.0 |
CVE-2026-61346 | Windows Graphics Kernel | Windows Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-61348 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-61361 | Windows DHCP Client | Windows DHCP Client Remote Code Execution | Important | 7.0 |
CVE-2026-61366 | Windows Network Connection Broker | Windows Network Connection Broker Elevation of Privilege | Important | 7.0 |
CVE-2026-61927 | Windows Bind Filter Driver | Windows Bind Filter Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-61929 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-61938 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.0 |
CVE-2026-61939 | Winlogon | Winlogon Elevation of Privilege | Important | 7.0 |
CVE-2026-62690 | Windows Push Notifications | Windows Push Notifications Elevation of Privilege | Important | 7.0 |
CVE-2026-62693 | Windows MIDI Service Module | Windows MIDI Service Module Elevation of Privileges | Important | 7.0 |
CVE-2026-62705 | Windows Bind Filter Driver | Microsoft Brokering File System Elevation of Privilege | Important | 7.0 |
CVE-2026-62723 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62724 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62725 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62726 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62727 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62728 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.0 |
CVE-2026-62729 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62734 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62748 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-62749 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-62753 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.0 |
CVE-2026-62766 | Windows Kerberos | Windows Kerberos Elevation of Privilege | Important | 7.0 |
CVE-2026-62773 | Windows Kerberos | Windows Kerberos Elevation of Privilege | Important | 7.0 |
CVE-2026-62774 | Windows Graphics Kernel | Windows Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-62780 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-62788 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-62892 | Capability Access Management Service (camsvc) | Capability Access Management Service (camsvc) Elevation of Privilege | Important | 7.0 |
CVE-2026-62897 | .NET Framework | .NET Framework Remote Code Execution | Important | 7.0 |
CVE-2026-62908 | Windows Backup Engine | Windows Backup Engine Elevation of Privilege | Important | 7.0 |
CVE-2026-65678 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-65776 | Windows Win32K | Windows Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-65778 | Windows Autopilot | Windows Autopilot Elevation of Privilege | Important | 7.0 |
CVE-2026-65779 | Windows Autopilot | Windows Autopilot Elevation of Privilege | Important | 7.0 |
CVE-2026-65780 | Windows Autopilot | Windows Autopilot Elevation of Privilege | Important | 7.0 |
CVE-2026-65781 | Windows Autopilot | Windows Autopilot Elevation of Privilege | Important | 7.0 |
CVE-2026-65782 | Windows Autopilot | Windows Autopilot Elevation of Privilege | Important | 7.0 |
CVE-2026-65783 | Windows Autopilot | Windows Autopilot Elevation of Privilege | Important | 7.0 |
CVE-2026-65788 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.0 |
CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-70307 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-62699 | Windows Universal Disk Format File System Driver (UDFS) | Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution | Important | 6.8 |
CVE-2026-62702 | Windows Graphics Kernel | Windows Graphics Kernel Denial of Service | Important | 6.8 |
CVE-2026-62769 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-62881 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-62883 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-65680 | Microsoft OneDrive | Microsoft OneDrive for MacOS Elevation of Privilege | Important | 6.7 |
CVE-2026-65795 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-65797 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-65798 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-65799 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-70304 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-70330 | Windows DNS | Windows DNS Elevation of Privilege | Important | 6.7 |
CVE-2026-61920 | Windows DNS | Windows DNS Server Remote Code Execution | Important | 6.6 |
CVE-2026-40375 | Dynamics Business Central | Microsoft Dynamics Business Central Information Disclosure | Important | 6.5 |
CVE-2026-47285 | Visual Studio Code | Visual Studio Code Information Disclosure | Important | 6.5 |
CVE-2026-58639 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 6.5 |
CVE-2026-59138 | Microsoft Remote Registry Service | Microsoft Remote Registry Service Denial of Service | Important | 6.5 |
CVE-2026-61345 | Microsoft Remote Registry Service | Microsoft Remote Registry Service Denial of Service | Important | 6.5 |
CVE-2026-61918 | Remote Desktop Client | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-61921 | Remote Desktop Client | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-61924 | Remote Desktop Client | Windows Remote Desktop Client Information Disclosure | Important | 6.5 |
CVE-2026-62714 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62715 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62716 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62718 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62720 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62742 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62745 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62750 | Windows HTTP Protocol Stack | Windows HTTP Protocol Stack Tampering | Important | 6.5 |
CVE-2026-62782 | Windows SMB Client | Windows SMB Client Information Disclosure | Important | 6.5 |
CVE-2026-62814 | Windows DHCP Server | Windows DHCP Server Information Disclosure | Important | 6.5 |
CVE-2026-62837 | Microsoft Office SharePoint | Microsoft SharePoint Server Information Disclosure | Important | 6.5 |
CVE-2026-62839 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 6.5 |
CVE-2026-62902 | .NET | .NET Information Disclosure | Important | 6.5 |
CVE-2026-62912 | Microsoft Exchange Server | Microsoft Exchange Server Denial of Service | Important | 6.5 |
CVE-2026-62915 | Microsoft Exchange Server | Microsoft Exchange Server Security Feature Bypass | Important | 6.5 |
CVE-2026-63512 | Microsoft Office SharePoint | Microsoft SharePoint Server Tampering | Important | 6.5 |
CVE-2026-63516 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 6.5 |
CVE-2026-65769 | Microsoft Teams Mobile | Microsoft Teams iOS Information Disclosure | Important | 6.5 |
CVE-2026-65785 | Windows DHCP Client | Windows DHCP Client Denial of Service | Important | 6.5 |
CVE-2026-65794 | Windows SMB Client | Windows SMB Client Information Disclosure | Important | 6.5 |
CVE-2026-65806 | Azure CycleCloud | Azure CycleCloud Information Disclosure | Important | 6.5 |
CVE-2026-65813 | Microsoft Exchange Server | Microsoft Exchange Server Elevation of Privilege | Important | 6.5 |
CVE-2026-66301 | Microsoft Dynamics 365 (on-premises) | Microsoft Dynamics 365 (On-Premises) Information Disclosure | Important | 6.5 |
CVE-2026-69550 | Windows App for Mac | Windows App for Mac Information Disclosure | Important | 6.5 |
CVE-2026-70327 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 6.5 |
CVE-2026-70328 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 6.5 |
CVE-2026-62708 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 6.4 |
CVE-2026-62899 | .NET | .NET Security Feature Bypass | Important | 5.9 |
CVE-2026-62900 | .NET | .NET Information Disclosure | Important | 5.9 |
CVE-2026-68819 | Windows Network File System | Windows Network File System Denial of Service | Important | 5.9 |
CVE-2026-59130 | AMD Zen | AMD Zen Information Disclosure | Important | 5.6 |
CVE-2026-59131 | AMD Zen | AMD Zen Information Disclosure | Important | 5.6 |
CVE-2026-54123 | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint for Mac Information Disclosure | Important | 5.5 |
CVE-2026-59128 | Windows Encrypting File System (EFS) | Windows Encrypting File System (EFS) Information Disclosure | Important | 5.5 |
CVE-2026-59135 | Microsoft Windows Search Component | Microsoft Windows Search Component Information Disclosure | Important | 5.5 |
CVE-2026-59136 | Microsoft COM for Windows | Microsoft COM for Windows Information Disclosure | Important | 5.5 |
CVE-2026-59137 | Windows Event Logging Service | Windows Event Logging Service Information Disclosure | Important | 5.5 |
CVE-2026-61347 | Windows Event Logging Service | Windows Event Logging Service Information Disclosure | Important | 5.5 |
CVE-2026-61360 | Windows GDI | Windows GDI Information Disclosure | Important | 5.5 |
CVE-2026-61928 | Windows Hello | Windows Hello Tampering | Important | 5.5 |
CVE-2026-61933 | Windows DWM Core Library | Windows DWM Core Library Information Disclosure | Important | 5.5 |
CVE-2026-61936 | Windows Defender Firewall Service | Windows Defender Firewall Service Security Feature Bypass | Important | 5.5 |
CVE-2026-62703 | Windows DWM Core Library | Windows DWM Core Library Information Disclosure | Important | 5.5 |
CVE-2026-62709 | Windows GDI+ | Windows GDI+ Information Disclosure | Important | 5.5 |
CVE-2026-62730 | Windows Wired AutoConfig Service | Windows Wired AutoConfig Service Information Disclosure | Important | 5.5 |
CVE-2026-62738 | Windows Management Instrumentation | Windows Management Instrumentation Information Disclosure | Important | 5.5 |
CVE-2026-62740 | Windows Imaging Component | Windows Imaging Component Information Disclosure | Important | 5.5 |
CVE-2026-62743 | Windows Win32K | Win32k Information Disclosure | Important | 5.5 |
CVE-2026-62746 | Windows Win32K | Win32k Information Disclosure | Important | 5.5 |
CVE-2026-62775 | Windows Container Isolation FS Filter Driver (unionfs.sys) | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure | Important | 5.5 |
CVE-2026-62786 | Windows Win32K | Win32k Information Disclosure | Important | 5.5 |
CVE-2026-62793 | Windows NTFS | Windows NTFS Information Disclosure | Important | 5.5 |
CVE-2026-62796 | Windows NTFS | Windows NTFS Information Disclosure | Important | 5.5 |
CVE-2026-62798 | Windows Win32K | Win32k Information Disclosure | Important | 5.5 |
CVE-2026-62842 | Microsoft Office | Microsoft Office Graphics Component Information Disclosure | Important | 5.5 |
CVE-2026-62887 | Windows NTFS | Windows NTFS Information Disclosure | Important | 5.5 |
CVE-2026-63517 | Microsoft Office | Microsoft Office Graphics Component Information Disclosure | Important | 5.5 |
CVE-2026-63521 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-63524 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-63528 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-63529 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-63530 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-63531 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-64899 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-64917 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-65662 | Windows GDI | Windows GDI Information Disclosure | Important | 5.5 |
CVE-2026-65784 | Windows NTFS | Windows NTFS Information Disclosure | Important | 5.5 |
CVE-2026-66806 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-66809 | Microsoft Office | Microsoft Office Graphics Component Information Disclosure | Important | 5.5 |
CVE-2026-66810 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-68797 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-68799 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-68802 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-68808 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-68809 | Microsoft Office PowerPoint | Powerpoint Information Disclosure | Important | 5.5 |
CVE-2026-68813 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-70310 | Microsoft Office Word | Microsoft Word Information Disclosure | Important | 5.5 |
CVE-2026-70312 | Microsoft Office PowerPoint | Powerpoint Information Disclosure | Important | 5.5 |
CVE-2026-70314 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-70315 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-70316 | Microsoft Office PowerPoint | Powerpoint Information Disclosure | Important | 5.5 |
CVE-2026-70317 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-70318 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 5.5 |
CVE-2026-70319 | Microsoft Office Word | Microsoft Office Word Information Disclosure | Important | 5.5 |
CVE-2026-70320 | Microsoft Office PowerPoint | Powerpoint Information Disclosure | Important | 5.5 |
CVE-2026-70322 | Microsoft Office PowerPoint | Powerpoint Information Disclosure | Important | 5.5 |
CVE-2026-70323 | Microsoft Office | Microsoft Office Information Disclosure | Important | 5.5 |
CVE-2026-70325 | Microsoft Office PowerPoint | Powerpoint Information Disclosure | Important | 5.5 |
CVE-2026-70348 | Windows Management Services | Windows Management Services Denial of Service | Important | 5.5 |
CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering | Important | 5.5 |
CVE-2026-70339 | Microsoft Edge (Chromium-based) | Microsoft Edge (Chromium-based) Remote Code Execution | Important | 5.4 |
CVE-2026-62757 | Windows Schannel | Windows Schannel Security Feature Bypass | Important | 5.3 |
CVE-2026-65777 | Windows Active Directory | Active Directory Security Feature Bypass | Important | 5.3 |
CVE-2026-61368 | Windows Hyper-V | Windows Hyper-V Information Disclosure | Important | 5.0 |
CVE-2026-61350 | Windows NTFS | Windows NTFS Information Disclosure | Important | 4.6 |
CVE-2026-62829 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-62917 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-64897 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-64902 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-64916 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-64922 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-62882 | Microsoft Office Outlook | Microsoft Outlook Spoofing | Important | 4.3 |
CVE-2026-56179 | Windows Network Address Translation (NAT) | Windows Network Address Translation (NAT) Spoofing | Moderate | 8.3 |
Published later in the month (54)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 6 Aug | CVE-2026-56162 | Azure SQL Database Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-65667 | Microsoft Teams Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-65770 | Azure Managed Instance for Apache Cassandra Remote Code Execution | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-65801 | Microsoft Exchange Online Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-65816 | Azure Arc Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69502 | Azure SQL Database Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69555 | Azure Arc Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69836 | Microsoft Entra ID Remote Code Execution | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-50481 | Azure Active Directory Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-50515 | Azure Service Bus Remote Code Execution | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-59115 | Microsoft Entra Provisioning Service Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-62830 | Azure SRE Agent Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-63509 | Microsoft Fabric Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-68782 | Azure SQL Database Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-68789 | Azure SQL Database Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69851 | Microsoft Entra ID Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-62873 | Microsoft 365 Admin Center Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-56161 | Azure Logic Apps Information Disclosure | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-62896 | Microsoft Teams Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69400 | Azure Logic Apps Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-70332 | Microsoft Office SharePoint Spoofing | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-50516 | Microsoft Azure Kubernetes Service Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-59118 | Copilot Cowork Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-62834 | Azure Data Factory Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-66309 | Azure SQL Database Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-68823 | Azure Confidential Ledger Remote Code Execution | Critical | Fixed by Microsoft |
| 18 Aug | CVE-2026-24301 | Microsoft Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-49163 | Application Insights Profiler Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-62869 | Azure Entra ID Spoofing | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-65668 | Microsoft Purview eDiscovery Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-62836 | Azure SQL Managed Instance Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-66800 | Azure Data Factory Information Disclosure | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69519 | Azure Stack HCI Information Disclosure | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69558 | Microsoft Partner Center Information Disclosure | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69419 | Azure Data Manager for Energy Remote Code Execution | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69543 | Azure Virtual Machines Elevation of Privilege | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-63522 | Azure SQL Database Elevation of Privilege | Critical | Fixed by Microsoft |
| 20 Aug | CVE-2026-69855 | Microsoft Copilot in Azure Information Disclosure | Critical | Fixed by Microsoft |
| 6 Aug | CVE-2026-62918 | Microsoft Teams Spoofing | Critical | Fixed by Microsoft |
| 28 Aug | CVE-2026-72984 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 28 Aug | CVE-2026-70341 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 14 Aug | CVE-2026-72970 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 14 Aug | CVE-2026-69414 | Microsoft Defender Elevation of Privilege | Important | Update |
| 20 Aug | CVE-2026-55013 | Windows Remote Help Defense Spoofing | Important | Update |
| 28 Aug | CVE-2026-66324 | Microsoft Edge (Chromium-based) Spoofing | Important | Update |
| 20 Aug | CVE-2026-70105 | Microsoft Word Information Disclosure | Important | Update |
| 20 Aug | CVE-2026-55015 | Microsoft Remote Help Denial of Service | Important | Update |
| 28 Aug | CVE-2026-66323 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 28 Aug | CVE-2026-66798 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 28 Aug | CVE-2026-62904 | Microsoft Edge (Chromium-based) Information Disclosure | Moderate | Update |
| 28 Aug | CVE-2026-70309 | Microsoft Edge (Chromium-based) Security Feature Bypass | Moderate | Update |
| 28 Aug | CVE-2026-70331 | Microsoft Edge for iOS Spoofing | Moderate | Update |
| 28 Aug | CVE-2026-58616 | Copilot Chat (Microsoft Edge) Information Disclosure | Moderate | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 7 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.