110/111 sources · synced 23:46 UTC Customize Public mode

Security

CVE detail from Microsoft's public MSRC CVRF API, cross-checked with CISA's Known Exploited Vulnerabilities catalog. Counts cover Microsoft-issued CVEs; republished third-party CVEs such as Chromium or Linux are hidden unless you include them.

CVEs · all collected releases

2 matches · most urgent first CSV Text
Fixed by KB5087063Clear
CVE Vulnerability Severity CVSSEPSSImpact StatusFixed by
CVE-2026-32177 .NET Elevation of Privilege Vulnerability.NET Important 7.30.6%Elevation of Privilege Revised 19 Jun
KB5087048KB5087049+18
CVE-2026-35433 .NET Elevation of Privilege Vulnerability.NET Important 7.30.6%Elevation of Privilege Revised 17 Jun
KB5087048KB5087049+16

CISA KEV · Microsoft additions

All 389
CVE-2026-65660 SharePoint
Microsoft SharePoint Code Injection Vulnerability
Added 25 Sep 2026Federal due date 28 Sep
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Added 8 Sep 2026Federal due date 22 Sep
Microsoft Windows Link Following Vulnerability
Added 8 Sep 2026Federal due date 22 Sep
CVE-2019-1068 SQL Server
Microsoft SQL Server Remote Code Execution Vulnerability
Added 26 Aug 2026Federal due date 29 Aug

Security news

All
Today4 items
Security baseline
LGPO.zip
Security baseline1.0Security Microsoft Security Compliance Toolkit artifacts

Exploited in other vendors' products

CISA KEV · Apple, Android, Chrome, Firefox, VMware, Oracle, Jamf · last 90 days
CVE-2026-86950 Apple · Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
Added 29 Sep 2026iOS and iPadOSmacOS
CVE-2026-58704 Google · Pixel
Google Pixel Improper Authorization Vulnerability
Added 16 Sep 2026Android
CVE-2026-87491 Google · Chromium V8
Google Chromium V8 Out of Bounds Write Vulnerability
Added 9 Sep 2026Google Chrome
CVE-2026-85046 Google · Chromium V8
Google Chromium V8 Type Confusion Vulnerability
Added 4 Sep 2026Google Chrome
CVE-2026-21962 Oracle · HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Added 24 Aug 2026Oracle WebLogic Server
CVE-2026-65400 Apple · macOS
Apple macOS Improper Authentication Vulnerability
Added 18 Aug 2026macOS
CVE-2026-59310 Broadcom · VMware vCenterRansomware
Broadcom VMware vCenter Path Traversal Vulnerability
Added 18 Aug 2026VMware vCenter Server
CVE-2026-46817 Oracle · E-Business Suite
Oracle E-Business Suite Improper Privilege Management Vulnerability
Added 15 Jul 2026Oracle E-Business Suite

Security baselines

Microsoft Security Compliance Toolkit downloads, as the download page lists them
  • Microsoft Security Compliance Toolkit artifacts · · 519 KB

    Revised 29 Sep 2026: the text changed

  • Microsoft Security Compliance Toolkit artifacts · · 871 KB

    Revised 29 Sep 2026: the text changed

  • Microsoft Security Compliance Toolkit artifacts · · 455 KB

    Revised 29 Sep 2026: the text changed

  • Microsoft Security Compliance Toolkit artifacts · · 1.5 MB

    Revised 29 Sep 2026: the text changed

11 more open

Sizes and dates are what Microsoft's download page reports; ChangeIntel does not download or check the files.

ChangeIntel is an independent tool and is not affiliated with or endorsed by Microsoft, Apple, Google, Broadcom (VMware), Jamf, Oracle, Mozilla, or any other vendor it covers. Product names are trademarks of their owners. Data comes from public sources listed on Sources; every item links to its original page. Dates and statuses can change after they are read. Privacy: no accounts or analytics, and your preferences stay in your browser. Terms: information, not advice. Built by Evotec. This is the public demo. It can also run on your own server, with your Microsoft 365 tenant and device data kept inside your network; Evotec can help you deploy and extend it.