Total CVEs

97

Critical

19

Important

76

Exploited

0

Publicly Disclosed

2

All CVEs this month 97

CVE Title Severity CVSS Product Exploited Disclosed Diffed
CVE-2026-21262 SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - Yes -
CVE-2026-23660 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability Important 7.8 Azure Portal Windows Admin Center - - -
CVE-2026-23664 Azure IoT Explorer Information Disclosure Vulnerability Important 7.5 Azure IoT Explorer - - -
CVE-2026-23667 Broadcast DVR Elevation of Privilege Vulnerability Important 7 Broadcast DVR - - -
CVE-2026-23668 Windows Graphics Component Elevation of Privilege Vulnerability Important 7 Microsoft Graphics Component - - -
CVE-2026-23669 RPC Runtime Library Remote Code Execution Vulnerability Important 8.8 RPC Runtime - - -
CVE-2026-23671 Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability Important 7 Windows Bluetooth RFCOM Protocol Driver - - -
CVE-2026-23672 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability Important 7.8 Windows Universal Disk Format File System Driver (UDFS) - - -
CVE-2026-23673 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Important 7.8 Windows Resilient File System (ReFS) - - -
CVE-2026-24282 Push message Routing Service Elevation of Privilege Vulnerability Important 5.5 Push Message Routing Service - - -
CVE-2026-24283 Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability Important 8.8 Windows File Server - - -
CVE-2026-24285 Win32k Elevation of Privilege Vulnerability Important 7 Windows Win32K - - -
CVE-2026-24287 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2026-24288 Windows Mobile Broadband Driver Remote Code Execution Vulnerability Important 6.8 Windows Mobile Broadband - - -
CVE-2026-24289 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2026-24290 Windows Projected File System Elevation of Privilege Vulnerability Important 7.8 Windows Projected File System - - -
CVE-2026-24291 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability Important 7.8 Windows Accessibility Infrastructure (ATBroker.exe) - - -
CVE-2026-24292 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability Important 7.8 Connected Devices Platform Service (Cdpsvc) - - -
CVE-2026-24293 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7.8 Windows Ancillary Function Driver for WinSock - - -
CVE-2026-24294 Windows SMB Server Elevation of Privilege Vulnerability Important 7.8 Windows SMB Server - - -
CVE-2026-24295 Windows Device Association Service Elevation of Privilege Vulnerability Important 7 Windows Device Association Service - - -
CVE-2026-24296 Windows Device Association Service Elevation of Privilege Vulnerability Important 7 Windows Device Association Service - - -
CVE-2026-24297 Windows Kerberos Security Feature Bypass Vulnerability Important 4.8 Windows Kerberos - - -
CVE-2026-25165 Performance Counters for Windows Elevation of Privilege Vulnerability Important 7.8 Windows Performance Counters - - -
CVE-2026-25166 Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability Important 7.8 Windows System Image Manager - - -
CVE-2026-25167 Microsoft Brokering File System Elevation of Privilege Vulnerability Important 7.4 Microsoft Brokering File System - - -
CVE-2026-25168 Windows Graphics Component Denial of Service Vulnerability Important 5.5 Microsoft Graphics Component - - -
CVE-2026-25169 Windows Graphics Component Denial of Service Vulnerability Important 5.5 Microsoft Graphics Component - - -
CVE-2026-25170 Windows Hyper-V Elevation of Privilege Vulnerability Important 7 Role: Windows Hyper-V - - -
CVE-2026-25171 Windows Authentication Elevation of Privilege Vulnerability Important 7 Windows Authentication Methods - - -
CVE-2026-25172 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2026-25173 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability Important 7.8 Windows Extensible File Allocation - - -
CVE-2026-25175 Windows NTFS Elevation of Privilege Vulnerability Important 7.8 Windows NTFS - - -
CVE-2026-25176 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7.8 Windows Ancillary Function Driver for WinSock - - -
CVE-2026-25177 Active Directory Domain Services Elevation of Privilege Vulnerability Important 8.8 Active Directory Domain Services - - -
CVE-2026-25178 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 Windows Ancillary Function Driver for WinSock - - -
CVE-2026-25179 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 Windows Ancillary Function Driver for WinSock - - -
CVE-2026-25180 Windows Graphics Component Information Disclosure Vulnerability Important 5.5 Microsoft Graphics Component - - -
CVE-2026-25181 GDI+ Information Disclosure Vulnerability Important 7.5 Windows GDI+ - - -
CVE-2026-25185 Windows Shell Link Processing Spoofing Vulnerability Important 5.3 Windows Shell Link Processing - - -
CVE-2026-25186 Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability Important 5.5 Windows Accessibility Infrastructure (ATBroker.exe) - - -
CVE-2026-25187 Winlogon Elevation of Privilege Vulnerability Important 7.8 Winlogon - - -
CVE-2026-25188 Windows Telephony Service Elevation of Privilege Vulnerability Important 8.8 Windows Telephony Service - - -
CVE-2026-25189 Windows DWM Core Library Elevation of Privilege Vulnerability Important 7.8 Windows DWM Core Library - - -
CVE-2026-25190 Windows GDI Remote Code Execution Vulnerability Important 7.8 Windows GDI - - -
CVE-2026-26105 Microsoft SharePoint Server Spoofing Vulnerability Important 9.3 Microsoft Office SharePoint - - -
CVE-2026-26111 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2026-26112 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2026-26113 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 Microsoft Office - - -
CVE-2026-26114 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 8.8 Microsoft Office SharePoint - - -
CVE-2026-23656 Windows App Installer Spoofing Vulnerability Important 5.9 Windows App Installer - - -
CVE-2026-20967 System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability Important 8.8 System Center Operations Manager - - -
CVE-2026-26121 Azure IOT Explorer Spoofing Vulnerability Important 7.5 Azure IoT Explorer - - -
CVE-2026-26115 SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - - -
CVE-2026-26116 SQL Server Elevation of Privilege Vulnerability Important 8.8 SQL Server - - -
CVE-2026-26128 Windows SMB Server Elevation of Privilege Vulnerability Important 7.8 Windows SMB Server - - -
CVE-2026-26131 .NET Elevation of Privilege Vulnerability Important 7.8 .NET - - -
CVE-2026-26132 Windows Kernel Elevation of Privilege Vulnerability Important 7.8 Windows Kernel - - -
CVE-2026-26134 Microsoft Office Elevation of Privilege Vulnerability Important 7.8 Microsoft Office - - -
CVE-2026-26127 .NET Denial of Service Vulnerability Important 7.5 .NET - Yes -
CVE-2026-23674 MapUrlToZone Security Feature Bypass Vulnerability Important 7.5 Windows MapUrlToZone - - -
CVE-2026-23651 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability Critical 6.7 Azure Compute Gallery - - -
CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability Critical 9.8 Microsoft Devices Pricing Program - - -
CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability Critical 6.7 Azure Compute Gallery - - -
CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability Critical 9.8 Payment Orchestrator Service - - -
CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability Critical 6.5 Azure Compute Gallery - - -
CVE-2026-26148 Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability Important 8.1 Azure Entra ID - - -
CVE-2026-32169 Azure Cloud Shell Elevation of Privilege Vulnerability Critical 9.8 Azure Cloud Shell - - -
CVE-2026-26139 Microsoft Purview Elevation of Privilege Vulnerability Critical 8.6 Microsoft Purview - - -
CVE-2026-26138 Microsoft Purview Elevation of Privilege Vulnerability Critical 10 Microsoft Purview - - -
CVE-2026-32191 Microsoft Bing Images Remote Code Execution Vulnerability Critical 9.8 Microsoft Bing Images - - -
CVE-2026-23658 Azure DevOps: msazure Elevation of Privilege Vulnerability Critical 9.8 Azure DevOps - - -
CVE-2026-26120 Microsoft Bing Tampering Vulnerability Critical 7.5 Microsoft Bing - - -
CVE-2026-23659 Azure Data Factory Information Disclosure Vulnerability Critical 7.5 Azure Data Factory - - -
CVE-2026-24299 M365 Copilot Information Disclosure Vulnerability Critical 5.3 M365 Copilot - - -
CVE-2026-26136 Microsoft Copilot Information Disclosure Vulnerability Critical 7.5 Microsoft Copilot - - -
CVE-2026-26137 Microsoft Exchange Elevation of Privilege Vulnerability Critical 9.9 Microsoft Exchange - - -
CVE-2026-32194 Microsoft Bing Images Remote Code Execution Vulnerability Critical 9.8 Microsoft Bing Images - - -
CVE-2026-23654 GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability Important 8.8 GitHub Repo: zero-shot-scfoundation - - -
CVE-2026-23661 Azure IoT Explorer Information Disclosure Vulnerability Important 7.5 Azure IoT Explorer - - -
CVE-2026-23662 Azure IoT Explorer Information Disclosure Vulnerability Important 7.5 Azure IoT Explorer - - -
CVE-2026-23665 Linux Azure Diagnostic extension (LAD) Elevation of Privilege Vulnerability Important 7.8 Azure Linux Virtual Machines - - -
CVE-2026-26106 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 8.8 Microsoft Office SharePoint - - -
CVE-2026-26107 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2026-26108 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2026-26109 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2026-26110 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 Microsoft Office - - -
CVE-2026-26117 Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability Important 7.8 Azure Windows Virtual Machine Agent - - -
CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability Important 8.8 Azure MCP Server - - -
CVE-2026-26123 Microsoft Authenticator Information Disclosure Vulnerability Important 5.5 Microsoft Authenticator - - -
CVE-2026-26130 ASP.NET Core Denial of Service Vulnerability Important 7.5 ASP.NET Core - - -
CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability Important 7.8 Azure Arc - - -
CVE-2026-26144 Microsoft Excel Information Disclosure Vulnerability Critical 4.7 Microsoft Office Excel - - -
CVE-2026-26133 M365 Copilot Information Disclosure Vulnerability Important 7.1 M365 Copilot - - -
CVE-2026-0385 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability Low 5 Microsoft Edge for Android - - -
CVE-2026-32187 Microsoft Edge (Chromium-based) Defense in Depth Vulnerability - Rejected Low - Microsoft Edge (Chromium-based) - - -

Threat Categories 8

Threat Category CVEs Critical
Elevation of Privilege 51 8
Remote Code Execution 19 5
Information Disclosure 14 5
Spoofing 5 -
Denial of Service 4 -
Security Feature Bypass 2 -
Defense in Depth 1 -
Tampering 1 1

Affected Products 65

Product CVEs Exploited
Microsoft Office Excel 5 -
Azure IoT Explorer 4 -
Microsoft Graphics Component 4 -
Windows Ancillary Function Driver for WinSock 4 -
Azure Compute Gallery 3 -
Microsoft Office 3 -
Microsoft Office SharePoint 3 -
SQL Server 3 -
Windows Kernel 3 -
Windows Routing and Remote Access Service (RRAS) 3 -
.NET 2 -
M365 Copilot 2 -
Microsoft Bing Images 2 -
Microsoft Purview 2 -
Windows Accessibility Infrastructure (ATBroker.exe) 2 -
Windows Device Association Service 2 -
Windows SMB Server 2 -
ASP.NET Core 1 -
Active Directory Domain Services 1 -
Azure Arc 1 -
Azure Cloud Shell 1 -
Azure Data Factory 1 -
Azure DevOps 1 -
Azure Entra ID 1 -
Azure Linux Virtual Machines 1 -
Azure MCP Server 1 -
Azure Portal Windows Admin Center 1 -
Azure Windows Virtual Machine Agent 1 -
Broadcast DVR 1 -
Connected Devices Platform Service (Cdpsvc) 1 -
GitHub Repo: zero-shot-scfoundation 1 -
Microsoft Authenticator 1 -
Microsoft Bing 1 -
Microsoft Brokering File System 1 -
Microsoft Copilot 1 -
Microsoft Devices Pricing Program 1 -
Microsoft Edge (Chromium-based) 1 -
Microsoft Edge for Android 1 -
Microsoft Exchange 1 -
Payment Orchestrator Service 1 -
Push Message Routing Service 1 -
RPC Runtime 1 -
Role: Windows Hyper-V 1 -
System Center Operations Manager 1 -
Windows App Installer 1 -
Windows Authentication Methods 1 -
Windows Bluetooth RFCOM Protocol Driver 1 -
Windows DWM Core Library 1 -
Windows Extensible File Allocation 1 -
Windows File Server 1 -
Windows GDI 1 -
Windows GDI+ 1 -
Windows Kerberos 1 -
Windows MapUrlToZone 1 -
Windows Mobile Broadband 1 -
Windows NTFS 1 -
Windows Performance Counters 1 -
Windows Projected File System 1 -
Windows Resilient File System (ReFS) 1 -
Windows Shell Link Processing 1 -
Windows System Image Manager 1 -
Windows Telephony Service 1 -
Windows Universal Disk Format File System Driver (UDFS) 1 -
Windows Win32K 1 -
Winlogon 1 -