Security
CVE detail from Microsoft's public MSRC CVRF API, cross-checked with CISA's Known Exploited Vulnerabilities catalog. Counts cover Microsoft-issued CVEs; republished third-party CVEs such as Chromium or Linux are hidden unless you include them.
| CVE | Vulnerability | Severity | CVSS | EPSS | Impact | Status | Fixed by |
|---|---|---|---|---|---|---|---|
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft Office SharePoint | Critical | 9.8 | 16% | Remote Code Execution | ExploitedCISA KEV · due 19 JulRevised 15 Jul | KB5002873KB5002874+1 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass VulnerabilityMicrosoft Office SharePoint | Critical | 9.1 | 18% | Security Feature Bypass | CISA KEV · due 21 Aug | KB5002882KB5002883+1 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft Office SharePoint | Critical | 9.8 | 3.0% | Remote Code Execution | CISA KEV · due 25 Jul | KB5002882KB5002883+1 |
| CVE-2026-65660 | Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint | Important | 8.8 | 2.1% | Remote Code Execution | CISA KEV · due 28 SepRevised 25 Sep | KB5002893KB5002894+3 |
| CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege VulnerabilityActive Directory Federation Services (AD FS) | Important | 7.8 | 0.3% | Elevation of Privilege | ExploitedCISA KEV · due 28 Jul | KB5099444KB5099445+4 |
| CVE-2026-81963 | Windows Update Stack Elevation of Privilege VulnerabilityWindows Update Stack | Important | 7.8 | 0.4% | Elevation of Privilege | ExploitedCISA KEV · due 22 SepRevised 15 Sep | KB5122871KB5122880+2 |
| CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege VulnerabilityWindows ALPC | Important | 7.8 | 3.6% | Elevation of Privilege | ExploitedCISA KEV · due 22 SepRevised 16 Sep | KB5122876KB5122878+4 |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWindows Ancillary Function Driver for WinSock | Important | 7.0 | 0.3% | Elevation of Privilege | ExploitedCISA KEV · due 25 Aug | KB5120228KB5120229+11 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege VulnerabilityMicrosoft Office SharePoint | Moderate | 5.3 | 1.0% | Elevation of Privilege | ExploitedCISA KEV · due 17 Jul | KB5002882KB5002883+1 |
CISA KEV · Microsoft additions
389 Microsoft CVEs listedCVE-2026-65660
SharePoint
Microsoft SharePoint Code Injection VulnerabilityCVE-2026-85880
Windows
Microsoft Windows Heap-Based Buffer Overflow VulnerabilityCVE-2026-81963
Windows
Microsoft Windows Link Following VulnerabilityCVE-2019-1068
SQL Server
Microsoft SQL Server Remote Code Execution VulnerabilityCVE-2026-55040
SharePoint
Microsoft SharePoint Weak Authentication VulnerabilityCVE-2026-33824
Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityCVE-2026-68820
Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityCVE-2026-50522
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-58644
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-56164
SharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityCVE-2026-56155
Active Directory Federation Services
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Security news
AllYesterday1 item
Thu 24 Sep2 items
Wed 23 Sep3 items
Tue 22 Sep1 item
Thu 17 Sep2 items
Tue 15 Sep1 item
Mon 14 Sep1 item
Thu 10 Sep1 item