Overview
On August 12, NSFOCUS CERT monitored that Microsoft released its August security update patch, fixing 421 security issues. These affect widely used products such as Windows, Microsoft Office, Azure, Visual Studio Code, Microsoft Exchange Server, etc., which include high-risk vulnerability types such as privilege escalation and remote code execution.
Among the vulnerabilities fixed in Microsoft’s monthly update this month, 62 are rated as Critical, 358 as Important, and 1 as Moderate. These include 1 vulnerability detected to be actively exploited in the wild:
Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability (CVE-2026-68820)
Relevant users are requested to update the patches as soon as possible for protection. For the complete list of vulnerabilities, please refer to the Appendix.
Reference Link:
https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug
Key Vulnerabilities
Vulnerabilities with significant impact have been filtered from this update based on product popularity and vulnerability importance. Relevant users should focus on these:
Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability (CVE-2026-68820):
Due to a use-after-free issue in the Windows socket driver (afd.sys), an authenticated local attacker can run a specially crafted malicious program on the system to trigger a race condition, thereby obtaining SYSTEM privileges. This vulnerability is actively exploited in the wild, with a CVSS score of 7.0.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
Windows User Profile Service Privilege Escalation Vulnerability (CVE-2026-62832):
A privilege escalation vulnerability exists in the Windows User Profile Service. An authenticated attacker can construct a specially crafted symbolic link that points to another high-privileged user’s registry hive file, thereby achieving privilege escalation. CVSS score of 7.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832
Windows DHCP Server Remote Code Execution Vulnerability (CVE-2026-62823):
Due to a heap-based buffer overflow vulnerability in Windows DHCP Server, an unauthenticated attacker can execute code on an adjacent network, with a CVSS score of 8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability (CVE-2026-62893):
Due to a use-after-free issue in the Windows Deployment Services TFTP Server, an unauthenticated attacker can send specially crafted requests to the TFTP service over the network, thereby achieving remote code execution. CVSS score of 9.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893
Windows DNS Server Remote Code Execution Vulnerability (CVE-2026-62817):
Due to an out-of-bounds write vulnerability in Windows DNS Server, an unauthenticated attacker can send specially crafted requests to the DNS server over the network, thereby executing arbitrary code on the target system. CVSS score of 8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability (CVE-2026-62816):
Due to a heap-based buffer overflow vulnerability in the Windows Reliable Multicast Transport Driver, an unauthenticated attacker on an adjacent network can send a series of specially crafted PGM packets, thereby executing arbitrary code on the target system. CVSS score of 8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62816
Microsoft Excel Remote Code Execution Vulnerability (CVE-2026-68804):
Due to a numeric truncation error in Microsoft Office Excel when parsing files, an attacker can craft a specially crafted malicious file and exploit the manipulated numeric values to trigger a heap-based buffer overflow, thereby executing arbitrary code on the target system. CVSS score of 7.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68804
Microsoft Office Graphics Component Remote Code Execution Vulnerability (CVE-2026-63526):
Due to a stack-based buffer overflow vulnerability in Microsoft Office, an attacker can send a specially crafted malicious Office file to entice a user to open it or use the preview pane, thereby executing arbitrary code. CVSS score of 7.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63526
Windows GDI+ Privilege Escalation Vulnerability (CVE-2026-62890/CVE-2026-62822):
A heap-based buffer overflow vulnerability exists in Windows GDI+. Due to Windows GDI+ failing to properly validate the size of input data when parsing specific graphics content, an authenticated local attacker can exploit this vulnerability to execute arbitrary code, thereby obtaining SYSTEM privileges. CVSS score of 7.8/8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62890
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62822
Windows DNS Server Remote Code Execution Vulnerability (CVE-2026-62878):
Due to a remote code execution vulnerability in Windows DNS Server, an unauthenticated attacker only needs to send specially crafted network requests to the target DNS server, thereby executing arbitrary code. CVSS score of 9.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878
Microsoft Excel Remote Code Execution Vulnerability (CVE-2026-68794/CVE-2026-68816):
Due to a buffer overflow vulnerability in Microsoft Excel, an unauthenticated attacker can entice a user to open a specially crafted malicious file, thereby achieving remote code execution. CVSS score of 7.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68794
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68816
Microsoft Office Word Remote Code Execution Vulnerability (CVE-2026-63518/CVE-2026-63525/CVE-2026-64907):
Due to buffer overflow or numeric truncation errors in Microsoft Office Word, an unauthenticated attacker can entice a user to open a specially crafted malicious file, thereby achieving remote code execution. CVSS score of 7.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63518
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63525
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64907
Microsoft Office Remote Code Execution Vulnerability (CVE-2026-63515/CVE-2026-70130/CVE-2026-63532/CVE-2026-64898/CVE-2026-64903/CVE-2026-64909/CVE-2026-64910/CVE-2026-64911/CVE-2026-65657):
Due to out-of-bounds read, buffer overflow, integer overflow, integer underflow, improper pointer dereference, or use-after-free vulnerabilities in Microsoft Office, an unauthenticated attacker can entice a user to open a specially crafted malicious file, thereby achieving remote code execution. CVSS score of 7.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63515
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70130
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63532
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64898
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64903
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64909
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64910
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64911
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65657
Microsoft SharePoint Server Privilege Escalation Vulnerability (CVE-2026-64921/CVE-2026-62827):
Due to an authentication bypass vulnerability in Microsoft SharePoint Server, an authenticated attacker can send specially crafted requests over the network, thereby achieving privilege escalation. CVSS score of 8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64921
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827
Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2026-65665):
Due to an insecure deserialization vulnerability in Microsoft SharePoint Server, an authenticated attacker can send specially crafted requests over the network, thereby achieving remote code execution. CVSS score of 8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65665
Windows DNS Server Remote Code Execution Vulnerability (CVE-2026-65789/CVE-2026-62820):
Due to use-after-free or race condition vulnerabilities in Windows DNS Server, an unauthenticated attacker can send specially crafted packets to the DNS service over the network, thereby achieving remote code execution. CVSS score of 8.1.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820
Windows SSTP Remote Code Execution Vulnerability (CVE-2026-62889):
Due to a memory corruption vulnerability in the Windows Secure Socket Tunneling Protocol (SSTP) when handling specially crafted network traffic, an unauthenticated attacker can send specially crafted packets to the SSTP service to trigger a race condition, thereby executing arbitrary code on the target system. CVSS score of 8.9.
Official Announcement Link:
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability (CVE-2026-62818):
Due to a use-after-free vulnerability in Windows Active Directory Certificate Services, an authenticated attacker can send specially crafted network requests, thereby executing arbitrary code. CVSS score of 8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62818
Remote Desktop Client Remote Code Execution Vulnerability (CVE-2026-62824):
Due to a stack-based buffer overflow vulnerability (CWE-121) in the Remote Desktop Client when handling specially crafted connection requests, an unauthenticated attacker can entice a user to connect to a malicious remote desktop server, thereby executing arbitrary code on the user’s system. CVSS score of 8.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62824
Microsoft QUIC Remote Code Execution Vulnerability (CVE-2026-62815):
Due to a use-after-free vulnerability in the Microsoft QUIC protocol implementation, an unauthenticated attacker can send specially crafted network traffic to an exposed QUIC service, thereby executing arbitrary code on the target system. CVSS score of 9.8.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815
Microsoft Office SharePoint Spoofing Vulnerability (CVE-2026-70332):
Due to a server-side request forgery (SSRF) vulnerability in Microsoft Office SharePoint, caused by insufficient validation when handling external resource requests, an unauthenticated attacker can trick the server into initiating unintended network requests, thereby probing sensitive information. CVSS score of 7.3.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332
Microsoft Exchange Server Privilege Escalation Vulnerability (CVE-2026-62911):
Due to a weak authentication path issue in Microsoft Exchange Server when handling authentication requests, an attacker can leverage capture-replay attacks to bypass the authentication mechanism, thereby elevating privileges on the target server. CVSS score of 8.0.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911
Azure Active Directory Privilege Escalation Vulnerability (CVE-2026-50481):
Due to a vulnerability in Azure Active Directory that allows modifying data presumed to be immutable, an authenticated attacker can exploit this vulnerability to manipulate critical data in the system, thereby achieving privilege escalation. CVSS score of 9.9.
Official Announcement Link:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50481
Scope of Impact
The following are some of the affected product versions for key focus vulnerabilities. For the scope of products affected by other vulnerabilities, please refer to the official announcement links.
| Vulnerability ID | Affected Product Versions |
|---|---|
| CVE-2026-62832 | Windows 11 Version 24H2 for ARM64-based Systems Windows 11 Version 24H2 for x64-based Systems Windows 11 Version 25H2 for ARM64-based Systems Windows 11 Version 25H2 for x64-based Systems Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2025 Windows Server 2025 (Server Core installation) Windows 10 Version 21H2 for 32-bit Systems Windows 10 Version 21H2 for ARM64-based Systems Windows 10 Version 21H2 for x64-based Systems Windows 10 Version 22H2 for 32-bit Systems Windows 10 Version 22H2 for ARM64-based Systems Windows 10 Version 22H2 for x64-based Systems Windows 11 Version 23H2 for ARM64-based Systems Windows 11 Version 23H2 for x64-based Systems Windows 11 Version 26H1 for ARM64-based Systems Windows 11 version 26H1 for x64-based Systems |
| CVE-2026-62817 | Windows 11 Version 24H2 for ARM64-based Systems Windows 11 Version 24H2 for x64-based Systems Windows 11 Version 25H2 for ARM64-based Systems Windows 11 Version 25H2 for x64-based Systems Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2025 Windows Server 2025 (Server Core installation) Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 21H2 for 32-bit Systems Windows 10 Version 21H2 for ARM64-based Systems Windows 10 Version 21H2 for x64-based Systems Windows 10 Version 22H2 for 32-bit Systems Windows 10 Version 22H2 for ARM64-based Systems Windows 10 Version 22H2 for x64-based Systems Windows 11 Version 23H2 for ARM64-based Systems Windows 11 Version 23H2 for x64-based Systems Windows 11 Version 26H1 for ARM64-based Systems Windows 11 version 26H1 for x64-based Systems Windows Server 2019 Windows Server 2019 (Server Core installation) |
| CVE-2026-62816 CVE-2026-62822 CVE-2026-62889 CVE-2026-62890 CVE-2026-68820 | Windows 11 Version 24H2 for ARM64-based Systems Windows 11 Version 24H2 for x64-based Systems Windows 11 Version 25H2 for ARM64-based Systems Windows 11 Version 25H2 for x64-based Systems Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2025 Windows Server 2025 (Server Core installation) Windows 10 Version 1607 for 32-bit Systems Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1809 for x64-based Systems Windows 10 Version 21H2 for 32-bit Systems Windows 10 Version 21H2 for ARM64-based Systems Windows 10 Version 21H2 for x64-based Systems Windows 10 Version 22H2 for 32-bit Systems Windows 10 Version 22H2 for ARM64-based Systems Windows 10 Version 22H2 for x64-based Systems Windows 11 Version 23H2 for ARM64-based Systems Windows 11 Version 23H2 for x64-based Systems Windows 11 Version 26H1 for ARM64-based Systems Windows 11 version 26H1 for x64-based Systems Windows Server 2012 Windows Server 2012 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 R2 (Server Core installation) Windows Server 2016 Windows Server 2016 (Server Core installation) Windows Server 2019 Windows Server 2019 (Server Core installation) |
| CVE-2026-63526 | Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft Office 2016 (32-bit edition) Microsoft Office 2016 (64-bit edition) Microsoft Office 2019 for 32-bit editions Microsoft Office 2019 for 64-bit editions Microsoft Office 365 for Mac Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 |
| CVE-2026-68794 CVE-2026-68804 CVE-2026-68816 | Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions Microsoft Office LTSC for Mac 2021 Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft Excel 2016 (32-bit edition) Microsoft Office LTSC for Mac 2024 Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office 365 for Mac Microsoft Excel 2016 (64-bit edition) |
| CVE-2026-63518 | Microsoft Office 365 for Mac Microsoft Outlook 2016 (64-bit edition) Microsoft Outlook 2016 (32-bit edition) Microsoft Office LTSC for Mac 2024 Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions Microsoft Office LTSC for Mac 2021 Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions |
| CVE-2026-63525 | Microsoft Office LTSC 2021 for 64-bit editions Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions Microsoft Word 2016 (64-bit edition) Microsoft Word 2016 (32-bit edition) Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2021 for 32-bit editions |
| CVE-2026-64907 | Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft Office LTSC for Mac 2021 Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions Microsoft Office 365 for Mac Microsoft Word 2016 (64-bit edition) Microsoft Word 2016 (32-bit edition) Microsoft Office LTSC for Mac 2024 Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions |
| CVE-2026-63515 CVE-2026-63532 CVE-2026-64903 CVE-2026-64909 CVE-2026-63526 | Microsoft Office 2016 (64-bit edition) Microsoft Office 2016 (32-bit edition) Microsoft Office LTSC for Mac 2024 Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions Microsoft Office LTSC for Mac 2021 Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions Microsoft Office 365 for Mac |
| CVE-2026-64898 CVE-2026-64910 CVE-2026-64911 CVE-2026-65657 | Microsoft Office LTSC for Mac 2024 Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions Microsoft Office LTSC for Mac 2021 Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions Microsoft Office 365 for Mac |
| CVE-2026-70130 | Microsoft Office LTSC 2024 for 64-bit editions Microsoft Office LTSC 2024 for 32-bit editions Microsoft Office LTSC 2021 for 32-bit editions Microsoft Office LTSC 2021 for 64-bit editions Microsoft 365 Apps for Enterprise for 64-bit Systems Microsoft 365 Apps for Enterprise for 32-bit Systems Microsoft Office 2019 for 64-bit editions Microsoft Office 2019 for 32-bit editions |
| CVE-2026-62827 CVE-2026-64921 | Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Server 2019 Microsoft SharePoint Enterprise Server 2016 |
| CVE-2026-65665 | Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Server 2019 |
| CVE-2026-70332 | Microsoft SharePoint Online |
| CVE-2026-62820 CVE-2026-65789 | Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2025 Windows Server 2025 (Server Core installation) Windows 10 Version 1607 for 32-bit Systems Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1809 for x64-based Systems Windows Server 2016 Windows Server 2016 (Server Core installation) Windows Server 2019 Windows Server 2019 (Server Core installation) |
| CVE-2026-62818 CVE-2026-62823 CVE-2026-62878 CVE-2026-62893 | Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2025 Windows Server 2025 (Server Core installation) Windows 10 Version 1607 for 32-bit Systems Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1809 for 32-bit Systems Windows 10 Version 1809 for x64-based Systems Windows Server 2012 Windows Server 2012 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 R2 (Server Core installation) Windows Server 2016 Windows Server 2016 (Server Core installation) Windows Server 2019 Windows Server 2019 (Server Core installation) |
| CVE-2026-62824 | Windows Server 2012 R2 (Server Core installation) Windows Server 2012 R2 Windows Server 2012 (Server Core installation) Windows Server 2012 Windows Server 2016 (Server Core installation) Windows Server 2016 Windows 10 Version 1607 for x64-based Systems Windows 10 Version 1607 for 32-bit Systems |
| CVE-2026-62815 | Windows 11 Version 24H2 for ARM64-based Systems Windows 11 Version 24H2 for x64-based Systems Windows 11 Version 25H2 for ARM64-based Systems Windows 11 Version 25H2 for x64-based Systems Windows Server 2022 Windows Server 2022 (Server Core installation) Windows Server 2025 Windows Server 2025 (Server Core installation) Windows 11 Version 23H2 for ARM64-based Systems Windows 11 Version 23H2 for x64-based Systems Windows 11 Version 26H1 for ARM64-based Systems Windows 11 version 26H1 for x64-based Systems |
| CVE-2026-62911 | Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 15 Microsoft Exchange Server Subscription Edition RTM Microsoft Exchange Server 2016 Cumulative Update 23 |
| CVE-2026-50481 | Azure Active Directory |
Mitigation
Patch Update
Currently, Microsoft official has released security patches to fix the above vulnerabilities for supported product versions. It is strongly recommended that affected users install the patches as soon as possible for protection. Official download link: https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug
Note: Due to network issues, computer environment issues, or other reasons, Windows Update patch updates may fail. Users should promptly check whether the patches were successfully updated after installing them. Right-click the Windows icon, select “Settings (N)”, select “Update & Security” and “Windows Update”, and view the prompt information on that page. You can also click “View update history” to view past updates. For updates that have not been successfully installed, you can click on the update name to jump to the official Microsoft download page. It is recommended that users click the link on that page to go to the “Microsoft Update Catalog” website to download the standalone package and install it.
Appendix: Vulnerability List
| Affected products | CVE No. | Vulnerability Title | Severity |
|---|---|---|---|
| Azure | CVE-2026-49163 | Application Insights Profiler Privilege Escalation Vulnerability | Critical |
| Azure | CVE-2026-50481 | Azure Active Directory Privilege Escalation Vulnerability | Critical |
| Microsoft Office | CVE-2026-50515 | Azure Service Bus Remote Code Execution Vulnerability | Critical |
| Azure | CVE-2026-50516 | Microsoft Azure Kubernetes Service Privilege Escalation Vulnerability | Critical |
| Azure | CVE-2026-56161 | Azure Logic Apps Information Disclosure Vulnerability | Critical |
| Azure | CVE-2026-56162 | Azure SQL Database Privilege Escalation Vulnerability | Critical |
| Azure | CVE-2026-59115 | Microsoft Entra Provisioning Service Privilege Escalation Vulnerability | Critical |
| Microsoft Dynamics | CVE-2026-59118 | Copilot Cowork Privilege Escalation Vulnerability | Critical |
| Windows | CVE-2026-62815 | Microsoft QUIC Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62816 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62817 | Windows DNS Server Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62818 | Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62819 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62820 | Windows DNS Server Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62822 | Windows GDI+ Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62823 | Windows DHCP Server Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62824 | Remote Desktop Client Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-62827 | Microsoft SharePoint Server Privilege Escalation Vulnerability | Critical |
| Azure | CVE-2026-62830 | Azure SRE Agent Privilege Escalation Vulnerability | Critical |
| Microsoft Office | CVE-2026-62836 | Azure SQL Managed Instance Privilege Escalation Vulnerability | Critical |
| Azure | CVE-2026-62869 | Azure Entra ID Spoofing Vulnerability | Critical |
| Azure | CVE-2026-62873 | Microsoft 365 Admin Center Privilege Escalation Vulnerability | Critical |
| Windows | CVE-2026-62878 | Windows DNS Server Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62889 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-62890 | Windows GDI+ Privilege Escalation Vulnerability | Critical |
| Windows | CVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-62896 | Microsoft Teams Privilege Escalation Vulnerability | Critical |
| Microsoft Exchange Server Subscription Edition RTM,Microsoft Exchange Server | CVE-2026-62911 | Microsoft Exchange Server Privilege Escalation Vulnerability | Critical |
| Microsoft Office | CVE-2026-62918 | Microsoft Teams Spoofing Vulnerability | Critical |
| Device | CVE-2026-63508 | Microsoft Planetary Computer Pro Privilege Escalation Vulnerability | Critical |
| Microsoft Office | CVE-2026-63513 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-63515 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-63518 | Microsoft Office Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-63519 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical |
| Azure | CVE-2026-63522 | Azure SQL Database Privilege Escalation Vulnerability | Critical |
| Microsoft Office | CVE-2026-63525 | Microsoft Office Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-63526 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-63532 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-64898 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-64903 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-64907 | Microsoft Office Word Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-64909 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-64910 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-64911 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-64921 | Microsoft SharePoint Server Privilege Escalation Vulnerability | Critical |
| Microsoft Office | CVE-2026-65657 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-65664 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-65665 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-65667 | Microsoft Teams Privilege Escalation Vulnerability | Critical |
| Azure | CVE-2026-65668 | Microsoft Purview eDiscovery Privilege Escalation Vulnerability | Critical |
| Windows | CVE-2026-65789 | Windows DNS Server Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-65791 | Windows iSCSI Target Service Remote Code Execution Vulnerability | Critical |
| Windows | CVE-2026-66799 | Windows Key Guard Privilege Escalation Vulnerability | Critical |
| Windows | CVE-2026-66802 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-66807 | Microsoft Office Graphics Component Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-68794 | Microsoft Excel Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-68804 | Microsoft Excel Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-68816 | Microsoft Excel Remote Code Execution Vulnerability | Critical |
| Azure | CVE-2026-68823 | Azure Confidential Ledger Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-70130 | Microsoft Office Remote Code Execution Vulnerability | Critical |
| Microsoft Office | CVE-2026-70332 | Microsoft Office SharePoint Spoofing Vulnerability | Critical |
| Windows | CVE-2026-71331 | Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability | Critical |
| Microsoft Dynamics | CVE-2026-40375 | Microsoft Dynamics Business Central Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-42976 | Remote Access Management service/API (RPC server) Privilege Escalation Vulnerability | Important |
| Visual Studio Code | CVE-2026-47285 | Visual Studio Code Information Disclosure Vulnerability | Important |
| Azure | CVE-2026-47299 | Azure Monitor Agent Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-49179 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-50472 | Windows LUA File Virtualization Filter Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-54113 | Remote Procedure Call Denial of Service Vulnerability | Important |
| System Center | CVE-2026-54123 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability | Important |
| Python extension for Visual Studio Code | CVE-2026-54981 | Visual Studio Code Python Extension Security Feature Bypass Vulnerability | Important |
| Windows | CVE-2026-54984 | Windows Imaging Component Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-56174 | Windows Narrator Braille Privilege Escalation Vulnerability | Important |
| Open Source Software | CVE-2026-57104 | Azure Storage Explorer Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-57105 | Microsoft Office SharePoint Spoofing Vulnerability | Important |
| PowerShell | CVE-2026-58612 | PowerShell Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-58639 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| .NET 8.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-58641 | .NET Privilege Escalation Vulnerability | Important |
| Visual Studio Code | CVE-2026-58650 | Visual Studio Code Security Feature Bypass Vulnerability | Important |
| Microsoft Office | CVE-2026-58651 | Microsoft Word Remote Code Execution Vulnerability | Important |
| Visual Studio Code | CVE-2026-59113 | Visual Studio Code Remote Code Execution Vulnerability | Important |
| PowerShell | CVE-2026-59119 | PowerShell Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-59122 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-59124 | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-59125 | Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulnerability | Important |
| Windows | CVE-2026-59126 | Windows Event Logging Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-59127 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-59128 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-59130 | AMD Zen Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-59131 | AMD Zen Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-59132 | Windows TCP/IP Denial of Service Vulnerability | Important |
| Windows | CVE-2026-59133 | Microsoft High Performance Computing (HPC) Pack Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-59134 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-59135 | Microsoft Windows Search Component Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-59136 | Microsoft COM for Windows Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-59137 | Windows Event Logging Service Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-59138 | Microsoft Remote Registry Service Denial of Service Vulnerability | Important |
| Windows | CVE-2026-61345 | Microsoft Remote Registry Service Denial of Service Vulnerability | Important |
| Windows | CVE-2026-61346 | Windows Graphics Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61347 | Windows Event Logging Service Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61348 | Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61349 | Windows Work Folder Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61350 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61352 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-61353 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61355 | Windows Sensor Data Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61356 | Windows Remote Desktop Services Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61357 | Application Information Services Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61358 | Windows Accessibility Infrastructure (ATBroker.exe) Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61359 | Windows Storage Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61360 | Windows GDI Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61361 | Windows DHCP Client Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-61363 | Remote Desktop Client Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-61364 | Windows Remote Desktop Services Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61365 | Windows Remote Desktop Services Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61366 | Windows Network Connection Broker Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61367 | Windows Remote Desktop Services Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61368 | Windows Hyper-V Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61918 | Windows Remote Desktop Client Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61920 | Windows DNS Server Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-61921 | Windows Remote Desktop Client Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61923 | Windows Display Enhancement Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61924 | Windows Remote Desktop Client Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61925 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61926 | Windows USB Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61927 | Windows Bind Filter Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61928 | Windows Hello Tampering Vulnerability | Important |
| Windows | CVE-2026-61929 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61930 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61932 | Windows DWM Core Library Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61933 | Windows DWM Core Library Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-61934 | Windows Bind Filter Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61936 | Windows Defender Firewall Service Security Feature Bypass Vulnerability | Important |
| Windows | CVE-2026-61937 | Windows HTTP.sys Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61938 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-61939 | Winlogon Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62688 | Windows MIDI Service Module Elevation of Privileges Vulnerability | Important |
| Windows | CVE-2026-62690 | Windows Push Notifications Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62692 | Windows Remote Desktop Services Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62693 | Windows MIDI Service Module Elevation of Privileges Vulnerability | Important |
| Windows | CVE-2026-62695 | Windows Storage Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62696 | Windows Program Compatibility Assistant Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62698 | Microsoft Digest Authentication Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62699 | Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62700 | Windows NTFS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62701 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62702 | Windows Graphics Kernel Denial of Service Vulnerability | Important |
| Windows | CVE-2026-62703 | Windows DWM Core Library Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62705 | Windows Bind Filter Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62707 | Windows Modern Device Management (MDM) Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62708 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62709 | Windows GDI+ Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62710 | Windows Device Association Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62711 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62712 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62713 | Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62714 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62715 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62716 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62717 | Windows Message Queuing Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62718 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62719 | Windows Message Queuing Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62720 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62721 | Windows User-Mode Power Service (UMPS) Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62722 | Windows Bind Filter Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62723 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62724 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62725 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62726 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62728 | Windows Common Log File System Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62729 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62730 | Windows Wired AutoConfig Service Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62732 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62733 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62734 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62735 | Windows HTTP.sys Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62736 | Windows DHCP Client Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62737 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62738 | Windows Management Instrumentation Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62739 | Windows HTTP.sys Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62740 | Windows Imaging Component Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62741 | Windows HTTP.sys Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62742 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62743 | Win32k Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62745 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62746 | Win32k Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62747 | Windows Device Association Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62748 | Windows Telephony Service Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62749 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62750 | Windows HTTP Protocol Stack Tampering Vulnerability | Important |
| Windows | CVE-2026-62751 | Windows Projected File System Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62752 | Windows Kerberos Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62753 | Windows HTTP.sys Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62754 | Windows Kerberos Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62755 | Windows DHCP Client Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62757 | Windows Schannel Security Feature Bypass Vulnerability | Important |
| Windows | CVE-2026-62758 | Windows Remote Access Connection Manager Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62761 | Windows DHCP Server Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62766 | Windows Kerberos Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62768 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62769 | Windows DNS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62770 | Windows Shell Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62771 | Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62772 | Windows Container Isolation FS Filter Driver (unionfs.sys) Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62773 | Windows Kerberos Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62774 | Windows Graphics Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62775 | Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62776 | Windows DHCP Server Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62777 | Windows License Manager Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62778 | Windows DNS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62779 | Windows Schannel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62780 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62781 | RPC Runtime Library Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62782 | Windows SMB Client Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62783 | Windows Remote Access Connection Manager Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62784 | Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62785 | Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62786 | Win32k Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62787 | Windows DNS Server Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62788 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62790 | Windows SMBv3 Server Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62792 | Windows TCP/IP Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62793 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62795 | Windows LDAP – Lightweight Directory Access Protocol Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62796 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62797 | Windows NTFS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62798 | Win32k Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62799 | Windows SMB Client Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62800 | Windows SMBv3 Server Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-62803 | Windows DHCP Server Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62807 | Windows DHCP Server Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62811 | Windows HTTP.sys Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62812 | Windows DHCP Server Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62814 | Windows DHCP Server Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-62829 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Windows | CVE-2026-62832 | Windows User Profile Service Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-62837 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-62839 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-62842 | Microsoft Office Graphics Component Information Disclosure Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62871 | .NET Privilege Escalation Vulnerability | Important |
| Microsoft .NET Framework | CVE-2026-62872 | .NET Framework Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62876 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62877 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62880 | Windows NTFS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62881 | Windows DNS Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-62882 | Microsoft Outlook Spoofing Vulnerability | Important |
| Windows | CVE-2026-62883 | Windows DNS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62885 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 10.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62886 | .NET Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62887 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62888 | Windows DWM Core Library Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62892 | Capability Access Management Service (camsvc) Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-62894 | Windows DWM Core Library Privilege Escalation Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 10.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,Microsoft .NET Framework,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62897 | .NET Framework Remote Code Execution Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 10.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62898 | Microsoft QUIC Information Disclosure Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62899 | .NET Security Feature Bypass Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62900 | .NET Information Disclosure Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62901 | .NET Denial of Service Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62902 | .NET Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-62908 | Windows Backup Engine Privilege Escalation Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 10.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-62909 | .NET Privilege Escalation Vulnerability | Important |
| Microsoft Exchange Server,Microsoft Exchange Server Subscription Edition RTM | CVE-2026-62910 | Microsoft Exchange Server Privilege Escalation Vulnerability | Important |
| Microsoft Exchange Server,Microsoft Exchange Server Subscription Edition RTM | CVE-2026-62912 | Microsoft Exchange Server Denial of Service Vulnerability | Important |
| Microsoft Exchange Server Subscription Edition RTM,Microsoft Exchange Server | CVE-2026-62913 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important |
| Microsoft Exchange Server Subscription Edition RTM,Microsoft Exchange Server | CVE-2026-62914 | Microsoft Exchange Server Spoofing Vulnerability | Important |
| Microsoft Exchange Server Subscription Edition RTM,Microsoft Exchange Server | CVE-2026-62915 | Microsoft Exchange Server Security Feature Bypass Vulnerability | Important |
| Microsoft Office | CVE-2026-62917 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-63512 | Microsoft SharePoint Server Tampering Vulnerability | Important |
| Microsoft Office | CVE-2026-63514 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-63516 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-63517 | Microsoft Office Graphics Component Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-63520 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-63521 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-63524 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-63527 | Microsoft Office Word Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-63528 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-63529 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-63530 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-63531 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-63533 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64897 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-64899 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-64900 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-64901 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64902 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-64904 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64905 | Microsoft Office Word Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64906 | Microsoft Access Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64908 | Microsoft Access Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64912 | Microsoft Access Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64914 | Microsoft Access Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64915 | Microsoft Office Word Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64916 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-64917 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-64919 | Microsoft Access Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64920 | Microsoft Access Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-64922 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-65656 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-65658 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-65660 | Microsoft SharePoint Server Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-65661 | Microsoft Office Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-65662 | Windows GDI Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-65663 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-65671 | Remote Access API Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65672 | Remote Access API Privilege Escalation Vulnerability | Important |
| Azure | CVE-2026-65673 | Microsoft Entra Connect Privilege Escalation Vulnerability | Important |
| Microsoft Visual Studio Code CoPilot Chat Extension | CVE-2026-65675 | CoPilot Chat Security Feature Bypass Vulnerability | Important |
| Windows | CVE-2026-65678 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65679 | Windows iSCSI Target Service Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-65680 | Microsoft OneDrive for MacOS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65681 | Windows iSCSI Target Service Denial of Service Vulnerability | Important |
| Microsoft Office | CVE-2026-65767 | Microsoft Teams for Android and iOS Spoofing Vulnerability | Important |
| Microsoft Office | CVE-2026-65768 | Microsoft Teams Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-65769 | Microsoft Teams iOS Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-65773 | Windows Kernel Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65774 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65775 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65776 | Windows Win32k Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65777 | Active Directory Security Feature Bypass Vulnerability | Important |
| Windows | CVE-2026-65778 | Windows Autopilot Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65779 | Windows Autopilot Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65780 | Windows Autopilot Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65781 | Windows Autopilot Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65782 | Windows Autopilot Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65783 | Windows Autopilot Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65784 | Windows NTFS Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-65785 | Windows DHCP Client Denial of Service Vulnerability | Important |
| Windows | CVE-2026-65786 | Desktop Window Manager Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65787 | Desktop Window Manager Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65788 | Desktop Window Manager Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65790 | Windows Message Queuing Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65794 | Windows SMB Client Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-65795 | Windows DNS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65796 | Windows iSCSI Target Service Denial of Service Vulnerability | Important |
| Windows | CVE-2026-65797 | Windows DNS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65798 | Windows DNS Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65799 | Windows DNS Privilege Escalation Vulnerability | Important |
| Azure | CVE-2026-65806 | Azure CycleCloud Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-65807 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft .NET Framework | CVE-2026-65810 | .NET Framework Privilege Escalation Vulnerability | Important |
| Power BI Report Server | CVE-2026-65811 | Power BI Remote Code Execution Vulnerability | Important |
| Microsoft Exchange Server,Microsoft Exchange Server Subscription Edition RTM | CVE-2026-65813 | Microsoft Exchange Server Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-65814 | Microsoft Windows Storage Port Driver Privilege Escalation Vulnerability | Important |
| Microsoft Dynamics | CVE-2026-65815 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Important |
| Microsoft Dynamics | CVE-2026-66301 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Important |
| Windows | CVE-2026-66804 | Microsoft Windows Cross Device Service Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-66805 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-66806 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-66808 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-66809 | Microsoft Office Graphics Component Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-66810 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-68792 | Microsoft Office Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-68793 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68795 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68796 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68797 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-68798 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68799 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-68800 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68801 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68802 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-68803 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68805 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68806 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68807 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68808 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-68809 | Powerpoint Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-68810 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68811 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68812 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68813 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-68814 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68815 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-68817 | Microsoft Excel Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-68819 | Windows Network File System Denial of Service Vulnerability | Important |
| Windows | CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | Important |
| Apps | CVE-2026-68821 | Windows Package Manager Privilege Escalation Vulnerability | Important |
| Visual Studio Code | CVE-2026-69278 | Visual Studio Code Security Feature Bypass Vulnerability | Important |
| Visual Studio Code | CVE-2026-69306 | Visual Studio Code Security Feature Bypass Vulnerability | Important |
| Visual Studio Code | CVE-2026-69320 | Visual Studio Code Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-70304 | Windows DNS Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-70306 | Microsoft Office SharePoint Spoofing Vulnerability | Important |
| Windows | CVE-2026-70307 | Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-70310 | Microsoft Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70311 | Microsoft Office Word Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-70312 | Powerpoint Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70313 | Microsoft PowerPoint Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-70314 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70315 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70316 | Powerpoint Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70317 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70318 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70319 | Microsoft Office Word Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70320 | Powerpoint Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70321 | Microsoft SharePoint Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-70322 | Powerpoint Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70323 | Microsoft Office Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70324 | Microsoft SharePoint Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-70325 | Powerpoint Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70326 | Microsoft SharePoint Server Privilege Escalation Vulnerability | Important |
| Microsoft Office | CVE-2026-70327 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70328 | Microsoft Excel Information Disclosure Vulnerability | Important |
| Microsoft Office | CVE-2026-70329 | Microsoft Outlook Remote Code Execution Vulnerability | Important |
| Windows | CVE-2026-70330 | Windows DNS Privilege Escalation Vulnerability | Important |
| Visual Studio Code | CVE-2026-70335 | GitHub Copilot and Visual Studio Code Privilege Escalation Vulnerability | Important |
| Visual Studio Code | CVE-2026-70336 | Visual Studio Code Remote Code Execution Vulnerability | Important |
| PowerShell | CVE-2026-70337 | Microsoft PowerShell Remote Code Execution Vulnerability | Important |
| PowerShell | CVE-2026-70338 | Microsoft PowerShell Security Feature Bypass Vulnerability | Important |
| Microsoft Edge (Chromium-based) | CVE-2026-70339 | Microsoft Edge Remote Code Execution Vulnerability | Important |
| Azure | CVE-2026-70340 | Azure CycleCloud Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-70344 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-70345 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-70346 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-70347 | Windows Installer Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-70348 | Windows Management Services Denial of Service Vulnerability | Important |
| Microsoft Visual Studio,.NET 8.0 installed on Windows,.NET 10.0 installed on Windows,.NET 8.0 installed on Mac OS,.NET 9.0 installed on Mac OS,Microsoft .NET Framework,.NET 9.0 installed on Linux,.NET 10.0 installed on Mac OS,.NET 9.0 installed on Windows,.NET 10.0 installed on Linux,.NET 8.0 installed on Linux | CVE-2026-70354 | .NET Core Remote Code Execution Vulnerability | Important |
| Microsoft Office | CVE-2026-70355 | Microsoft SharePoint Server Privilege Escalation Vulnerability | Important |
| Windows | CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability | Important |
| Windows | CVE-2026-56179 | Windows Network Address Translation (NAT) Spoofing Vulnerability | Moderate |
Statement
This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and/or indirect consequences and losses caused by transmitting and/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add/delete any information to/from it, or use this advisory for commercial purposes without permission from NSFOCUS.
About NSFOCUS
NSFOCUS, a pioneering leader in cybersecurity, is dedicated to safeguarding telecommunications, Internet service providers, hosting providers, and enterprises from sophisticated cyberattacks.
Founded in 2000, NSFOCUS operates globally with over 3000 employees at two headquarters in Beijing, China, and Santa Clara, CA, USA, and over 50 offices worldwide. It has a proven track record of protecting over 25% of the Fortune Global 500 companies, including four of the five largest banks and six of the world’s top ten telecommunications companies.
Leveraging technical prowess and innovation, NSFOCUS delivers a comprehensive suite of security solutions, including the Intelligent Security Operations Platform (ISOP) for modern SOC, DDoS Protection, Continuous Threat Exposure Management (CTEM) Service and Web Application and API Protection (WAAP). All the solutions and services are augmented by the Security Large Language Model (SecLLM), ML, patented algorithms and other cutting-edge research achievements developed by NSFOCUS.