Security
CVE detail from Microsoft's public MSRC CVRF API, cross-checked with CISA's Known Exploited Vulnerabilities catalog. Counts cover Microsoft-issued CVEs; republished third-party CVEs such as Chromium or Linux are hidden unless you include them.
663Microsoft CVEsreleased Tue 14 Jul
77Critical56 need an update · rest fixed service-side
3Exploited in the wild
1Publicly disclosed
5In CISA KEV
100Revised since release
Act first · July 2026
Exploited, KEV-listed, or publicly disclosedPatch next · critical, "exploitation more likely", or top 5% EPSS · needs an update85
Showing 8 of 85All critical
By impact
By product family
| CVE | Vulnerability | Severity | CVSS | EPSS | Impact | Status | Fixed by |
|---|---|---|---|---|---|---|---|
| CVE-2026-55140 | Microsoft Office Remote Code Execution VulnerabilityMicrosoft Office | Critical | 7.8 | 0.5% | Remote Code Execution | KB5002748KB5002830 | |
| CVE-2026-56189 | Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Windows Media Foundation | Critical | 7.8 | 0.4% | Remote Code Execution | KB5099444KB5099445+7 | |
| CVE-2026-58542 | Windows Media Remote Code Execution VulnerabilityWindows Media | Critical | 7.8 | 0.4% | Remote Code Execution | KB5099536KB5101649+1 | |
| CVE-2026-54127 | Windows Hyper-V Elevation of Privilege VulnerabilityWindows Hyper-V | Critical | 7.4 | 0.3% | Elevation of Privilege | KB5099536KB5099540+2 | |
| CVE-2026-50392 | Windows Secure Kernel Mode Elevation of Privilege VulnerabilityWindows Secure Kernel Mode | Critical | 7.0 | 0.3% | Elevation of Privilege | KB5099536KB5101649+1 | |
| CVE-2026-48561 | Microsoft Edge Copilot Remote Code Execution VulnerabilityCopilot Chat (Microsoft Edge) | Critical | — | 0.9% | Remote Code Execution | Revised 24 Jul | — |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityMicrosoft Azure Kubernetes Service | Critical | 10.0 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-56191 | Microsoft Exchange Online Tampering VulnerabilityMicrosoft Exchange Online | Critical | 10.0 | 0.9% | Tampering | Service-side fix | |
| CVE-2026-57106 | Data Quality Elevation of Privilege VulnerabilityData Quality | Critical | 10.0 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-58275 | Azure DNS Elevation of Privilege VulnerabilityAzure DNS | Critical | 10.0 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityAzure App Service | Critical | 10.0 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege VulnerabilityAzure Key Vault | Critical | 10.0 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution VulnerabilityAzure Cosmos DB | Critical | 10.0 | 0.9% | Remote Code Execution | Service-side fix | |
| CVE-2026-45499 | Azure OpenAI Elevation of Privilege VulnerabilityAzure OpenAI | Critical | 9.9 | 0.8% | Elevation of Privilege | Revised 9 Sep | Service-side fix |
| CVE-2026-50517 | Microsoft M365 Copilot Remote Code Execution VulnerabilityM365 Copilot | Critical | 9.9 | 1.7% | Remote Code Execution | Service-side fix | |
| CVE-2026-54120 | Microsoft Surface Remote Code Execution VulnerabilityMicrosoft Surface | Critical | 9.9 | 1.0% | Remote Code Execution | Service-side fix | |
| CVE-2026-57100 | Microsoft Entra Provisioning Service Elevation of Privilege VulnerabilityMicrosoft Entra Provisioning Service (SyncFabric) | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-55010 | Minecraft Bedrock Dedicated Server Remote Code Execution VulnerabilityMinecraft Bedrock Dedicated Server | Critical | 9.8 | 1.0% | Remote Code Execution | Service-side fix | |
| CVE-2026-56165 | Microsoft Account Remote Code Execution VulnerabilityMicrosoft Account | Critical | 9.8 | 1.0% | Remote Code Execution | Service-side fix | |
| CVE-2026-41106 | Microsoft 365 Copilot Elevation of Privilege VulnerabilityM365 Copilot | Critical | 9.3 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62835 | Azure Portal Information Disclosure VulnerabilityAzure Portal | Critical | 9.3 | 1.0% | Information Disclosure | Revised 24 Jul | Service-side fix |
| CVE-2026-54998 | Microsoft Exchange Online Elevation of Privilege VulnerabilityMicrosoft Exchange Online | Critical | 8.8 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-56167 | Azure AI Search Elevation of Privilege VulnerabilityAzure AI Search | Critical | 8.5 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-35425 | Azure API Management (APIM) Remote Code Execution VulnerabilityAzure API Management (APIM) | Critical | 8.0 | 0.7% | Remote Code Execution | Service-side fix | |
| CVE-2026-49159 | Microsoft Graph Information Disclosure VulnerabilityMicrosoft Graph | Critical | 6.5 | 1.0% | Information Disclosure | Service-side fix | |
| CVE-2026-26145 | Microsoft Azure Synapse Elevation of Privilege VulnerabilityAzure Synapse | Critical | 4.8 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-56160 | Azure Red Hat OpenShift (ARO) Elevation of Privilege VulnerabilityAzure Red Hat OpenShift (ARO) | Critical | — | 0.8% | Elevation of Privilege | Service-side fix |
CISA KEV · Microsoft additions
389 Microsoft CVEs listedCVE-2026-65660
SharePoint
Microsoft SharePoint Code Injection VulnerabilityCVE-2026-85880
Windows
Microsoft Windows Heap-Based Buffer Overflow VulnerabilityCVE-2026-81963
Windows
Microsoft Windows Link Following VulnerabilityCVE-2019-1068
SQL Server
Microsoft SQL Server Remote Code Execution VulnerabilityCVE-2026-55040
SharePoint
Microsoft SharePoint Weak Authentication VulnerabilityCVE-2026-33824
Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityCVE-2026-68820
Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityCVE-2026-50522
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-58644
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-56164
SharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityCVE-2026-56155
Active Directory Federation Services
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Security news
AllFri 25 Sep1 item
Thu 24 Sep2 items
Wed 23 Sep3 items
Tue 22 Sep1 item
Thu 17 Sep2 items
Tue 15 Sep1 item
Mon 14 Sep1 item
Thu 10 Sep1 item