Security
CVE detail from Microsoft's public MSRC CVRF API, cross-checked with CISA's Known Exploited Vulnerabilities catalog. Counts cover Microsoft-issued CVEs; republished third-party CVEs such as Chromium or Linux are hidden unless you include them.
456Microsoft CVEsreleased Tue 11 Aug
84Critical44 need an update · rest fixed service-side
1Exploited in the wild
3Publicly disclosed
2In CISA KEV
135Revised since release
Act first · August 2026
Exploited, KEV-listed, or publicly disclosedPatch next · critical, "exploitation more likely", or top 5% EPSS · needs an update75
Showing 8 of 75All critical
By impact
By product family
| CVE | Vulnerability | Severity | CVSS | EPSS | Impact | Status | Fixed by |
|---|---|---|---|---|---|---|---|
| CVE-2026-69502 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 10.0 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69555 | Azure Arc Elevation of Privilege VulnerabilityAzure Arc | Critical | 10.0 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69836 | Microsoft Entra ID Remote Code Execution VulnerabilityMicrosoft Entra ID | Critical | 10.0 | 1.5% | Remote Code Execution | Revised 21 Aug | Service-side fix |
| CVE-2026-50481 | Azure Active Directory Elevation of Privilege VulnerabilityAzure Active Directory | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-50515 | Azure Service Bus Remote Code Execution VulnerabilityAzure Service Bus | Critical | 9.9 | 1.7% | Remote Code Execution | Service-side fix | |
| CVE-2026-59115 | Microsoft Entra Provisioning Service Elevation of Privilege VulnerabilityMicrosoft Entra Provisioning Service (SyncFabric) | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62830 | Azure SRE Agent Elevation of Privilege VulnerabilityAzure SRE Agent | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-63509 | Microsoft Fabric Elevation of Privilege VulnerabilityMicrosoft Fabric | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-68782 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-68789 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69851 | Microsoft Entra ID Elevation of Privilege VulnerabilityAzure Active Directory | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62873 | Microsoft 365 Admin Center Elevation of Privilege VulnerabilityMicrosoft 365 Admin Center | Critical | 9.8 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-56161 | Azure Logic Apps Information Disclosure VulnerabilityAzure Logic Apps | Critical | 9.6 | 0.7% | Information Disclosure | Service-side fix | |
| CVE-2026-62896 | Microsoft Teams Elevation of Privilege VulnerabilityMicrosoft Teams | Critical | 9.6 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69400 | Azure Logic Apps Elevation of Privilege VulnerabilityAzure Logic Apps | Critical | 9.6 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-70332 | Microsoft Office SharePoint Spoofing VulnerabilityMicrosoft Office SharePoint | Critical | 9.6 | 0.9% | Spoofing | Service-side fix | |
| CVE-2026-50516 | Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityMicrosoft Azure Kubernetes Service | Critical | 9.4 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-59118 | Copilot Cowork Elevation of Privilege VulnerabilityCopilot Cowork | Critical | 9.3 | 0.7% | Elevation of Privilege | Revised 11 Aug | Service-side fix |
| CVE-2026-62834 | Azure Data Factory Elevation of Privilege VulnerabilityAzure Data Factory | Critical | 9.3 | 0.5% | Elevation of Privilege | Service-side fix | |
| CVE-2026-66309 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 9.1 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-68823 | Azure Confidential Ledger Remote Code Execution VulnerabilityAzure Confidential Ledger | Critical | 9.1 | 0.9% | Remote Code Execution | Service-side fix | |
| CVE-2026-24301 | Microsoft Copilot Information Disclosure VulnerabilityMicrosoft Copilot | Critical | 8.8 | 4.1% | Information Disclosure | Revised 25 Aug | Service-side fix |
| CVE-2026-49163 | Application Insights Profiler Elevation of Privilege VulnerabilityApplication Insights Profiler | Critical | 8.8 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62869 | Azure Entra ID Spoofing VulnerabilityAzure Entra ID | Critical | 8.8 | 0.4% | Spoofing | Service-side fix | |
| CVE-2026-65668 | Microsoft Purview eDiscovery Elevation of Privilege VulnerabilityMicrosoft Purview eDiscovery | Critical | 8.8 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62836 | Azure SQL Managed Instance Elevation of Privilege VulnerabilityAzure SQL Managed Instance | Critical | 8.7 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-66800 | Azure Data Factory Information Disclosure VulnerabilityAzure Data Factory | Critical | 8.6 | 1.0% | Information Disclosure | Service-side fix | |
| CVE-2026-69519 | Azure Stack HCI Information Disclosure VulnerabilityAzure Stack HCI | Critical | 8.6 | 1.0% | Information Disclosure | Service-side fix | |
| CVE-2026-69558 | Microsoft Partner Center Information Disclosure VulnerabilityMicrosoft Partner Center | Critical | 8.6 | 1.0% | Information Disclosure | Service-side fix | |
| CVE-2026-69419 | Azure Data Manager for Energy Remote Code Execution VulnerabilityAzure Data Manager for Energy | Critical | 8.5 | 0.7% | Remote Code Execution | Service-side fix | |
| CVE-2026-69543 | Azure Virtual Machines Elevation of Privilege VulnerabilityAzure Virtual Machines | Critical | 8.5 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-63522 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 7.8 | 0.3% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69855 | Microsoft Copilot in Azure Information Disclosure VulnerabilityMicrosoft Copilot in Azure | Critical | 7.7 | 0.8% | Information Disclosure | Service-side fix | |
| CVE-2026-62918 | Microsoft Teams Spoofing VulnerabilityMicrosoft Teams | Critical | 7.5 | 0.5% | Spoofing | Service-side fix |
CISA KEV · Microsoft additions
389 Microsoft CVEs listedCVE-2026-65660
SharePoint
Microsoft SharePoint Code Injection VulnerabilityCVE-2026-85880
Windows
Microsoft Windows Heap-Based Buffer Overflow VulnerabilityCVE-2026-81963
Windows
Microsoft Windows Link Following VulnerabilityCVE-2019-1068
SQL Server
Microsoft SQL Server Remote Code Execution VulnerabilityCVE-2026-55040
SharePoint
Microsoft SharePoint Weak Authentication VulnerabilityCVE-2026-33824
Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityCVE-2026-68820
Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityCVE-2026-50522
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-58644
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-56164
SharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityCVE-2026-56155
Active Directory Federation Services
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Security news
AllFri 25 Sep1 item
Thu 24 Sep2 items
Wed 23 Sep3 items
Tue 22 Sep1 item
Thu 17 Sep2 items
Tue 15 Sep1 item
Mon 14 Sep1 item
Thu 10 Sep1 item