Security
CVE detail from Microsoft's public MSRC CVRF API, cross-checked with CISA's Known Exploited Vulnerabilities catalog. Counts cover Microsoft-issued CVEs; republished third-party CVEs such as Chromium or Linux are hidden unless you include them.
| CVE | Vulnerability | Severity | CVSS | EPSS | Impact | Status | Fixed by |
|---|---|---|---|---|---|---|---|
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft Office SharePoint | Critical | 9.8 | 16% | Remote Code Execution | ExploitedCISA KEV · due 19 JulExploit code publicRevised 15 Jul | KB5002873KB5002874+1 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass VulnerabilityMicrosoft Office SharePoint | Critical | 9.1 | 18% | Security Feature Bypass | CISA KEV · due 21 AugExploit code public | KB5002882KB5002883+1 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege VulnerabilityMicrosoft Defender | Important | 7.8 | 0.4% | Elevation of Privilege | ExploitedCISA KEV · due 3 JunDisclosedRevised 26 May | — |
| CVE-2026-45498 | Microsoft Defender Denial of Service VulnerabilityMicrosoft Defender | Low | 4.0 | 1.3% | Denial of Service | ExploitedCISA KEV · due 3 JunDisclosedRevised 26 May | — |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft Office SharePoint | Critical | 9.8 | 3.0% | Remote Code Execution | CISA KEV · due 25 Jul | KB5002882KB5002883+1 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing VulnerabilityMicrosoft Exchange Server | Critical | 8.1 | 0.5% | Spoofing | ExploitedCISA KEV · due 29 MayRevised 14 Jul | KB5094139KB5094140+2 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft Office SharePoint | Important | 8.8 | 2.7% | Remote Code Execution | CISA KEV · due 4 JulRevised 26 May | KB5002863KB5002868+1 |
| CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege VulnerabilityActive Directory Federation Services (AD FS) | Important | 7.8 | 0.3% | Elevation of Privilege | ExploitedCISA KEV · due 28 Jul | KB5099444KB5099445+4 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege VulnerabilityMicrosoft Office SharePoint | Moderate | 5.3 | 1.0% | Elevation of Privilege | ExploitedCISA KEV · due 17 Jul | KB5002882KB5002883+1 |
CISA KEV · Microsoft additions
All 389Security news
AllExploited in other vendors' products
CISA KEV · Apple, Android, Chrome, Firefox, VMware, Oracle, Jamf · last 90 daysSecurity baselines
Microsoft Security Compliance Toolkit downloads, as the download page lists them- 1.0LGPO.zipMicrosoft Security Compliance Toolkit artifacts · · 519 KB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 871 KB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 455 KB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.5 MB
Revised 29 Sep 2026: the text changed
11 more open
-
Microsoft Security Compliance Toolkit artifacts ·
· 313 KB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.5 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.3 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.5 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.2 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.2 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.3 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.2 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.3 MB
Revised 29 Sep 2026: the text changed
-
Microsoft Security Compliance Toolkit artifacts ·
· 1.3 MB
Revised 29 Sep 2026: the text changed
- Microsoft Security Compliance Toolkit artifacts · · 1.2 MB
Sizes and dates are what Microsoft's download page reports; ChangeIntel does not download or check the files.