Security
CVE detail from Microsoft's public MSRC CVRF API, cross-checked with CISA's Known Exploited Vulnerabilities catalog. Counts cover Microsoft-issued CVEs; republished third-party CVEs such as Chromium or Linux are hidden unless you include them.
998Microsoft CVEsreleased Tue 8 Sep
132Critical105 need an update · rest fixed service-side
2Exploited in the wild
0Publicly disclosed
2In CISA KEV
149Revised since release
Act first · September 2026
Exploited, KEV-listed, or publicly disclosedPatch next · critical, "exploitation more likely", or top 5% EPSS · needs an update155
Showing 8 of 155All critical
By impact
By product family
| CVE | Vulnerability | Severity | CVSS | EPSS | Impact | Status | Fixed by |
|---|---|---|---|---|---|---|---|
| CVE-2026-69854 | Spring Cloud Azure Elevation of Privilege VulnerabilitySpring Cloud Azure | Critical | 9.0 | 0.7% | Elevation of Privilege | — | |
| CVE-2026-62895 | Azure Arc SQL Server Extension Elevation of Privilege VulnerabilityAzure Arc | Important | 8.8 | 0.8% | Elevation of Privilege | — | |
| CVE-2026-83948 | Microsoft Azure CLI Remote Code Execution VulnerabilityMicrosoft Azure CLI | Important | 8.0 | 0.6% | Remote Code Execution | — | |
| CVE-2026-77909 | Azure CycleCloud Information Disclosure VulnerabilityAzure CycleCloud | Important | 7.7 | 0.9% | Information Disclosure | — | |
| CVE-2026-84003 | Microsoft Authentication Library (MSAL) for Node.js Spoofing VulnerabilityMicrosoft Authentication Library (MSAL) for Node.js | Important | 7.4 | 0.6% | Spoofing | — | |
| CVE-2026-81349 | Azure HDInsight Ambari Elevation of Privilege VulnerabilityAzure HDInsights | Important | 7.2 | 1.0% | Elevation of Privilege | — | |
| CVE-2026-62874 | Azure Billing Elevation of Privilege VulnerabilityAzure Billing | Critical | 10.0 | 0.4% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69399 | Azure Arc Elevation of Privilege VulnerabilityAzure Arc | Critical | 10.0 | 0.5% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69865 | Microsoft Container Registry Elevation of Privilege VulnerabilityMicrosoft Container Registry | Critical | 10.0 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-70200 | Azure Logic Apps Elevation of Privilege VulnerabilityAzure Logic Apps | Critical | 10.0 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-70352 | Azure AI Language Elevation of Privilege VulnerabilityAzure AI Language | Critical | 10.0 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege VulnerabilityMicrosoft Azure Active Directory B2C | Critical | 10.0 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-83944 | Azure Logic Apps Elevation of Privilege VulnerabilityAzure Logic Apps | Critical | 10.0 | 0.4% | Elevation of Privilege | Service-side fix | |
| CVE-2026-85889 | Azure AI Foundry Elevation of Privilege VulnerabilityAzure AI Foundry | Critical | 10.0 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-83941 | Entra ID Elevation of Privilege VulnerabilityEntra ID | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-85878 | Azure Database for PostgreSQL Elevation of Privilege VulnerabilityAzure Database for PostgreSQL | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-87701 | Azure Cosmos DB Elevation of Privilege VulnerabilityAzure Cosmos DB | Critical | 9.6 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-70009 | Azure Arc Elevation of Privilege VulnerabilityAzure Arc | Critical | 9.3 | 0.5% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62916 | Microsoft Entra ID Elevation of Privilege VulnerabilityMicrosoft Entra ID | Critical | 9.1 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-68791 | Azure Machine Learning Information Disclosure VulnerabilityAzure Machine Learning | Critical | 8.6 | 0.5% | Information Disclosure | Service-side fix | |
| CVE-2026-69857 | Azure Cosmos DB Spoofing VulnerabilityAzure Cosmos DB | Critical | 8.5 | 0.6% | Spoofing | Service-side fix | |
| CVE-2026-83946 | Azure Portal Spoofing VulnerabilityAzure Portal | Critical | 8.2 | 0.3% | Spoofing | Service-side fix | |
| CVE-2026-85917 | Azure AI Foundry Elevation of Privilege VulnerabilityAzure AI Foundry | Critical | 7.5 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62906 | Microsoft Discovery Studio Information Disclosure VulnerabilityMicrosoft Discovery Studio | Critical | 7.4 | 0.9% | Information Disclosure | Service-side fix |
CISA KEV · Microsoft additions
389 Microsoft CVEs listedCVE-2026-65660
SharePoint
Microsoft SharePoint Code Injection VulnerabilityCVE-2026-85880
Windows
Microsoft Windows Heap-Based Buffer Overflow VulnerabilityCVE-2026-81963
Windows
Microsoft Windows Link Following VulnerabilityCVE-2019-1068
SQL Server
Microsoft SQL Server Remote Code Execution VulnerabilityCVE-2026-55040
SharePoint
Microsoft SharePoint Weak Authentication VulnerabilityCVE-2026-33824
Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityCVE-2026-68820
Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityCVE-2026-50522
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-58644
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-56164
SharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityCVE-2026-56155
Active Directory Federation Services
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Security news
AllFri 25 Sep1 item
Thu 24 Sep2 items
Wed 23 Sep3 items
Tue 22 Sep1 item
Thu 17 Sep2 items
Tue 15 Sep1 item
Mon 14 Sep1 item
Thu 10 Sep1 item