110/111 sources · synced 22:45 UTC Customize Public mode

Security update fixing 57 CVEs

0Windows versions
57CVEs fixed · 5 critical
0Exploited or in CISA KEV
0Open known issues affecting it
YesRestart required (per MSRC)

Known issues in this update

Windows release health

No known issues listed

Windows release health lists no issues from this KB or the update it builds on.

Issues this update resolves

No resolved issues listed

Windows release health names no issues fixed by this KB.

Security fixes

57 Microsoft CVEs · most urgent first
CVE Vulnerability Severity CVSSEPSSImpact Status
CVE-2026-41089 Windows Netlogon Remote Code Execution VulnerabilityWindows Netlogon Critical 9.81.0%Remote Code Execution
CVE-2026-41096 Windows DNS Client Remote Code Execution VulnerabilityMicrosoft Windows DNS Critical 9.81.0%Remote Code Execution
CVE-2026-40403 Windows Graphics Component Remote Code Execution VulnerabilityWindows Win32K - GRFX Critical 8.80.3%Remote Code Execution
CVE-2026-35421 Windows GDI Remote Code Execution VulnerabilityWindows GDI Critical 7.80.5%Remote Code Execution
CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution VulnerabilityWindows Native WiFi Miniport Driver Critical 7.50.3%Remote Code Execution Revised 15 May
CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityWindows Message Queuing Important 8.80.5%Remote Code Execution
CVE-2026-40415 Windows TCP/IP Remote Code Execution VulnerabilityWindows TCP/IP Important 8.10.7%Remote Code Execution
CVE-2026-33834 Windows Event Logging Service Elevation of Privilege VulnerabilityWindows Event Logging Service Important 7.80.3%Elevation of Privilege
CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityWindows Cloud Files Mini Filter Driver Important 7.80.3%Elevation of Privilege Revised 17 Sep
CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege VulnerabilityWindows TCP/IP Important 7.80.3%Elevation of Privilege
Showing the 10 most urgent of 57All 57 CVEs
ChangeIntel is an independent tool and is not affiliated with or endorsed by Microsoft, Apple, Google, Broadcom (VMware), Jamf, Oracle, Mozilla, or any other vendor it covers. Product names are trademarks of their owners. Data comes from public sources listed on Sources; every item links to its original page. Dates and statuses can change after they are read. Privacy: no accounts or analytics, and your preferences stay in your browser. Terms: information, not advice. Built by Evotec. This is the public demo. It can also run on your own server, with your Microsoft 365 tenant and device data kept inside your network; Evotec can help you deploy and extend it.