110/111 sources · synced 22:45 UTC Customize Public mode

Security update fixing 9 CVEs

0Windows versions
9CVEs fixed · 2 critical
1Exploited or in CISA KEV
0Open known issues affecting it
—Restart required (per MSRC)

Known issues in this update

Windows release health

No known issues listed

Windows release health lists no issues from this KB or the update it builds on.

Issues this update resolves

No resolved issues listed

Windows release health names no issues fixed by this KB.

Security fixes

9 Microsoft CVEs · most urgent first
CVE Vulnerability Severity CVSSEPSSImpact Status
CVE-2026-45659 Microsoft SharePoint Remote Code Execution VulnerabilityMicrosoft Office SharePoint Important 8.82.7%Remote Code Execution CISA KEV · due 4 JulRevised 26 May
CVE-2026-40365 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint Critical 8.81.1%Remote Code Execution
CVE-2026-40367 Microsoft Word Remote Code Execution VulnerabilityMicrosoft Office Word Critical 8.40.4%Remote Code Execution Revised 20 May
CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint Important 8.82.3%Remote Code Execution
CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint Important 8.82.3%Remote Code Execution Revised 27 May
CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint Important 8.82.3%Remote Code Execution
CVE-2026-40357 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint Important 8.82.3%Remote Code Execution
CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint Important 8.02.1%Remote Code Execution
CVE-2026-47294 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Office SharePoint Important 8.01.2%Remote Code Execution Revised 10 Jun
ChangeIntel is an independent tool and is not affiliated with or endorsed by Microsoft, Apple, Google, Broadcom (VMware), Jamf, Oracle, Mozilla, or any other vendor it covers. Product names are trademarks of their owners. Data comes from public sources listed on Sources; every item links to its original page. Dates and statuses can change after they are read. Privacy: no accounts or analytics, and your preferences stay in your browser. Terms: information, not advice. Built by Evotec. This is the public demo. It can also run on your own server, with your Microsoft 365 tenant and device data kept inside your network; Evotec can help you deploy and extend it.