Patch Tuesday Archive
Patch Tuesday April 2026
Total CVEs
181
Critical
23
Important
155
Exploited
2
Publicly Disclosed
1
All CVEs this month 181
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2026-32210 | Microsoft Dynamics 365 (online) Spoofing Vulnerability | Critical | 7.5 |
Microsoft Dynamics 365 (Online) | - | - | - |
| CVE-2026-33102 | Microsoft 365 Copilot Elevation of Privilege Vulnerability | Critical | 9.3 |
M365 Copilot | - | - | - |
| CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability | Critical | 9.8 |
Microsoft Bing | - | - | - |
| CVE-2026-20930 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-23653 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | Important | 6.5 |
GitHub Copilot and Visual Studio Code | - | - | - |
| CVE-2026-25184 | Applocker Filter Driver (applockerfltr.sys) Elevation of Privilege Vulnerability | Important | 7 |
Applocker Filter Driver (applockerfltr.sys) | - | - | Yes |
| CVE-2026-20945 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-23670 | Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability | Important | 5.7 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2026-26149 | Microsoft Power Apps Desktop Client Spoofing Vulnerability | Important | 9 |
Microsoft Power Apps | - | - | - |
| CVE-2026-26151 | Remote Desktop Spoofing Vulnerability | Important | 7.1 |
Windows Remote Desktop | - | - | - |
| CVE-2026-26154 | Windows Server Update Service (WSUS) Tampering Vulnerability | Important | 7.5 |
Windows Server Update Service | - | - | - |
| CVE-2026-26155 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | Important | 6.5 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2026-26160 | Remote Desktop Licensing Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2026-26161 | Windows Sensor Data Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Sensor Data Service | - | - | - |
| CVE-2026-26162 | Windows OLE Elevation of Privilege Vulnerability | Important | 7.8 |
Windows OLE | - | - | - |
| CVE-2026-26165 | Windows Shell Elevation of Privilege Vulnerability | Important | 7 |
Windows Shell | - | - | - |
| CVE-2026-26166 | Windows Shell Elevation of Privilege Vulnerability | Important | 7 |
Windows Shell | - | - | - |
| CVE-2026-26167 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-26174 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | Important | 7 |
Windows Server Update Service | - | - | - |
| CVE-2026-26175 | Windows Boot Manager Security Feature Bypass Vulnerability | Important | 4.6 |
Windows Boot Manager | - | - | - |
| CVE-2026-26179 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2026-26180 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2026-26181 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Brokering File System | - | - | - |
| CVE-2026-26183 | Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows RPC API | - | - | - |
| CVE-2026-27906 | Windows Hello Security Feature Bypass Vulnerability | Important | 4.4 |
Windows Hello | - | - | - |
| CVE-2026-27907 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2026-27908 | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability | Important | 7 |
Windows TDI Translation Driver (tdx.sys) | - | - | - |
| CVE-2026-27915 | Windows UPnP Device Host Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-27917 | Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) Elevation of Privilege Vulnerability | Important | 7 |
Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) | - | - | - |
| CVE-2026-27918 | Windows Shell Elevation of Privilege Vulnerability | Important | 7 |
Windows Shell | - | - | - |
| CVE-2026-27919 | Windows UPnP Device Host Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-27921 | Windows TDI Translation Driver (tdx.sys) Elevation of Privilege Vulnerability | Important | 7 |
Windows TCP/IP | - | - | - |
| CVE-2026-27924 | Desktop Window Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Desktop Window Manager | - | - | - |
| CVE-2026-27926 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2026-27927 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7 |
Windows Projected File System | - | - | - |
| CVE-2026-27929 | Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows LUAFV | - | - | - |
| CVE-2026-27931 | Windows GDI Information Disclosure Vulnerability | Important | 5.5 |
Windows GDI | - | - | - |
| CVE-2026-32071 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | Important | 7.5 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2026-32073 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-32075 | Windows UPnP Device Host Elevation of Privilege Vulnerability | Important | 7 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-32081 | Package Catalog Information Disclosure Vulnerability | Important | 5.5 |
Windows File Explorer | - | - | - |
| CVE-2026-32082 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | Important | 7 |
Windows SSDP Service | - | - | - |
| CVE-2026-32083 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | Important | 7 |
Windows SSDP Service | - | - | - |
| CVE-2026-32085 | Remote Procedure Call Information Disclosure Vulnerability | Important | 5.5 |
Windows Remote Procedure Call | - | - | - |
| CVE-2026-32087 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Important | 7 |
Function Discovery Service (fdwsd.dll) | - | - | - |
| CVE-2026-32089 | Windows Speech Brokered Api Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Speech Brokered Api | - | - | - |
| CVE-2026-32090 | Windows Speech Brokered Api Elevation of Privilege Vulnerability | Important | 7 |
Windows Speech Brokered Api | - | - | - |
| CVE-2026-32093 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Important | 7 |
Function Discovery Service (fdwsd.dll) | - | - | - |
| CVE-2026-32152 | Desktop Window Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Desktop Window Manager | - | - | - |
| CVE-2026-32154 | Desktop Window Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Desktop Window Manager | - | - | - |
| CVE-2026-32156 | Windows UPnP Device Host Remote Code Execution Vulnerability | Important | 7.4 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-32157 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2026-32158 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-32159 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-32160 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-0390 | UEFI Secure Boot Security Feature Bypass Vulnerability | Important | 6.7 |
Windows Boot Loader | - | - | - |
| CVE-2026-32165 | Windows User Interface Core Elevation of Privilege Vulnerability | Important | 7.8 |
Windows User Interface Core | - | - | - |
| CVE-2026-32167 | SQL Server Elevation of Privilege Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2026-32168 | Azure Monitor Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Monitor Agent | - | - | - |
| CVE-2026-32178 | .NET Spoofing Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2026-32181 | Connected User Experiences and Telemetry Service Denial of Service Vulnerability | Important | 5.5 |
Microsoft Windows | - | - | - |
| CVE-2026-32184 | Microsoft High Performance Compute (HPC) Pack Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft High Performance Compute Pack (HPC) | - | - | - |
| CVE-2026-32188 | Microsoft Excel Information Disclosure Vulnerability | Important | 7.1 |
Microsoft Office Excel | - | - | - |
| CVE-2026-32189 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-32192 | Azure Monitor Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Monitor Agent | - | - | - |
| CVE-2026-32195 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2026-32202 | Windows Shell Spoofing Vulnerability | Important | 4.3 |
Windows Shell | Yes | - | - |
| CVE-2026-32215 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2026-32216 | Windows Redirected Drive Buffering System Denial of Service Vulnerability | Important | 5.5 |
Windows Redirected Drive Buffering | - | - | - |
| CVE-2026-32217 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2026-32218 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2026-32219 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Brokering File System | - | - | - |
| CVE-2026-32220 | UEFI Secure Boot Security Feature Bypass Vulnerability | Important | 4.4 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2026-32221 | Windows Graphics Component Remote Code Execution Vulnerability | Important | 8.4 |
Microsoft Graphics Component | - | - | - |
| CVE-2026-32222 | Windows Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2026-32223 | Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability | Important | 6.8 |
Windows USB Print Driver | - | - | Yes |
| CVE-2026-32224 | Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | Important | 7 |
Windows Server Update Service | - | - | - |
| CVE-2026-32226 | .NET Framework Denial of Service Vulnerability | Important | 5.9 |
.NET Framework | - | - | - |
| CVE-2026-33095 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2026-33096 | HTTP.sys Denial of Service Vulnerability | Important | 7.5 |
Windows HTTP.sys | - | - | - |
| CVE-2026-33098 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Container Isolation FS Filter Driver | - | - | - |
| CVE-2026-33116 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET, .NET Framework, Visual Studio | - | - | - |
| CVE-2026-33120 | Microsoft SQL Server Remote Code Execution Vulnerability | Important | 8.8 |
SQL Server | - | - | - |
| CVE-2026-33822 | Microsoft Word Information Disclosure Vulnerability | Important | 6.1 |
Microsoft Office Word | - | - | - |
| CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Defender | - | Yes | - |
| CVE-2026-33826 | Windows Active Directory Remote Code Execution Vulnerability | Critical | 8 |
Windows Active Directory | - | - | - |
| CVE-2026-32212 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | Important | 5.5 |
Universal Plug and Play (upnp.dll) | - | - | - |
| CVE-2026-32186 | Microsoft Bing Elevation of Privilege Vulnerability | Critical | 9.8 |
Microsoft Bing | - | - | - |
| CVE-2026-33107 | Azure Databricks Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Databricks | - | - | - |
| CVE-2026-20928 | Windows Recovery Environment Security Feature Bypass Vulnerability | Important | 4.6 |
Windows Recovery Environment Agent | - | - | - |
| CVE-2026-20806 | Windows COM Server Information Disclosure Vulnerability | Important | 5.5 |
Windows COM | - | - | - |
| CVE-2026-23657 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2026-23666 | .NET Framework Denial of Service Vulnerability | Critical | 7.5 |
.NET Framework | - | - | - |
| CVE-2026-26143 | Microsoft PowerShell Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft PowerShell | - | - | - |
| CVE-2026-26152 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Important | 7 |
Windows Cryptographic Services | - | - | - |
| CVE-2026-26153 | Windows Encrypted File System (EFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Encrypting File System (EFS) | - | - | - |
| CVE-2026-26156 | Windows Hyper-V Remote Code Execution Vulnerability | Important | 7.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2026-26159 | Remote Desktop Licensing Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Desktop Licensing Service | - | - | - |
| CVE-2026-26163 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2026-26168 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-26169 | Windows Kernel Memory Information Disclosure Vulnerability | Important | 6.1 |
Windows Kernel Memory | - | - | - |
| CVE-2026-26170 | PowerShell Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft PowerShell | - | - | - |
| CVE-2026-26172 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-26173 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-26176 | Windows Client Side Caching driver (csc.sys) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Client Side Caching driver (csc.sys) | - | - | - |
| CVE-2026-26177 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-26178 | Windows Advanced Rasterization Platform Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Advanced Rasterization Platform | - | - | - |
| CVE-2026-26182 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-26184 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System | - | - | - |
| CVE-2026-27909 | Windows Search Service Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows Search Component | - | - | - |
| CVE-2026-27910 | Windows Installer Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Installer | - | - | - |
| CVE-2026-27911 | Windows User Interface Core Elevation of Privilege Vulnerability | Important | 7.8 |
Windows User Interface Core | - | - | - |
| CVE-2026-27912 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 8 |
Windows Kerberos | - | - | - |
| CVE-2026-27913 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 7.7 |
Windows BitLocker | - | - | - |
| CVE-2026-27914 | Microsoft Management Console Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Management Console | - | - | - |
| CVE-2026-27916 | Windows UPnP Device Host Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-27920 | Windows UPnP Device Host Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-27922 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-27923 | Desktop Window Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Desktop Window Manager | - | - | - |
| CVE-2026-27925 | Windows UPnP Device Host Information Disclosure Vulnerability | Important | 6.5 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-27928 | Windows Hello Security Feature Bypass Vulnerability | Important | 8.7 |
Windows Hello | - | - | - |
| CVE-2026-27930 | Windows GDI Information Disclosure Vulnerability | Important | 5.5 |
Windows GDI | - | - | - |
| CVE-2026-32068 | Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability | Important | 7 |
Windows SSDP Service | - | - | - |
| CVE-2026-32069 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System | - | - | - |
| CVE-2026-32070 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Common Log File System Driver | - | - | - |
| CVE-2026-32072 | Active Directory Spoofing Vulnerability | Important | 6.2 |
Windows Active Directory | - | - | - |
| CVE-2026-32074 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System | - | - | - |
| CVE-2026-32076 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2026-32077 | Windows UPnP Device Host Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Universal Plug and Play (UPnP) Device Host | - | - | - |
| CVE-2026-32079 | Web Account Manager Information Disclosure Vulnerability | Important | 5.5 |
Windows File Explorer | - | - | - |
| CVE-2026-32080 | Windows WalletService Elevation of Privilege Vulnerability | Important | 7 |
Windows WalletService | - | - | - |
| CVE-2026-32084 | Windows Print Spooler Information Disclosure Vulnerability | Important | 5.5 |
Windows File Explorer | - | - | - |
| CVE-2026-32086 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Important | 7 |
Function Discovery Service (fdwsd.dll) | - | - | - |
| CVE-2026-32088 | Windows Biometric Service Security Feature Bypass Vulnerability | Important | 5.7 |
Windows Biometric Service | - | - | - |
| CVE-2026-32091 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Brokering File System | - | - | - |
| CVE-2026-32149 | Windows Hyper-V Remote Code Execution Vulnerability | Important | 7.3 |
Role: Windows Hyper-V | - | - | - |
| CVE-2026-32150 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Important | 7 |
Function Discovery Service (fdwsd.dll) | - | - | - |
| CVE-2026-32151 | Windows Shell Information Disclosure Vulnerability | Important | 6.5 |
Windows Shell | - | - | - |
| CVE-2026-32153 | Windows Speech Runtime Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Windows Speech | - | - | - |
| CVE-2026-32155 | Desktop Window Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Desktop Window Manager | - | - | - |
| CVE-2026-32162 | Windows COM Elevation of Privilege Vulnerability | Important | 8.4 |
Windows COM | - | - | - |
| CVE-2026-32163 | Windows User Interface Core Elevation of Privilege Vulnerability | Important | 7.8 |
Windows User Interface Core | - | - | - |
| CVE-2026-32164 | Windows User Interface Core Elevation of Privilege Vulnerability | Important | 7.8 |
Windows User Interface Core | - | - | - |
| CVE-2026-32171 | Azure Logic Apps Elevation of Privilege Vulnerability | Important | 8.8 |
Azure Logic Apps | - | - | - |
| CVE-2026-32176 | SQL Server Elevation of Privilege Vulnerability | Important | 7.8 |
SQL Server | - | - | - |
| CVE-2026-32190 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-32196 | Windows Admin Center Spoofing Vulnerability | Important | 6.1 |
Windows Admin Center | - | - | - |
| CVE-2026-32197 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-32198 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-32199 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-32200 | Microsoft PowerPoint Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office PowerPoint | - | - | - |
| CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 6.5 |
Microsoft Office SharePoint | Yes | - | - |
| CVE-2026-26171 | .NET Denial of Service Vulnerability | Important | 7.5 |
.NET | - | - | - |
| CVE-2026-32203 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2026-32225 | Windows Shell Security Feature Bypass Vulnerability | Important | 8.8 |
Windows Shell | - | - | - |
| CVE-2026-33099 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-33100 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-33101 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2026-33103 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Dynamics 365 (on-premises) | - | - | - |
| CVE-2026-33104 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K - GRFX | - | - | - |
| CVE-2026-33114 | Microsoft Word Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office Word | - | - | - |
| CVE-2026-33115 | Microsoft Word Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office Word | - | - | - |
| CVE-2026-33827 | Windows TCP/IP Remote Code Execution Vulnerability | Critical | 8.1 |
Windows TCP/IP | - | - | - |
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | Critical | 9.8 |
Windows IKE Extension | - | - | - |
| CVE-2026-33829 | Windows Snipping Tool Spoofing Vulnerability | Moderate | 4.3 |
Windows Snipping Tool | - | - | - |
| CVE-2026-32214 | Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability | Important | 5.5 |
Universal Plug and Play (upnp.dll) | - | - | - |
| CVE-2026-33118 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2026-33119 | Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | Moderate | 5.4 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2026-32078 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System | - | - | - |
| CVE-2026-32173 | Azure SRE Agent Information Disclosure Vulnerability | Critical | 7.5 |
Azure SRE Agent | - | - | - |
| CVE-2026-40372 | ASP.NET Core Elevation of Privilege Vulnerability | Important | 9.1 |
ASP.NET Core | - | - | - |
| CVE-2026-26150 | Microsoft Purview eDiscovery Elevation of Privilege Vulnerability | Critical | 10 |
Microsoft Purview | - | - | - |
| CVE-2026-24303 | Microsoft Partner Center Elevation of Privilege Vulnerability | Critical | 9.6 |
Microsoft Partner Center | - | - | - |
| CVE-2026-35431 | Microsoft Entra ID Entitlement Management Spoofing Vulnerability | Critical | 10 |
Microsoft Entra ID Entitlement Management | - | - | - |
| CVE-2026-32172 | Microsoft Power Apps Remote Code Execution Vulnerability | Critical | 8 |
Microsoft Power Apps | - | - | - |
| CVE-2026-21515 | Azure IoT Central Elevation of Privilege Vulnerability | Critical | 9.9 |
Azure IOT Central | - | - | - |
| CVE-2026-26135 | Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability | Critical | 8.8 |
Azure Custom Locations Resource Provider (RP) | - | - | - |
| CVE-2026-32211 | Azure MCP Server Information Disclosure Vulnerability | Critical | 7.5 |
Azure MCP Server | - | - | - |
| CVE-2026-32213 | Azure AI Foundry Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure AI Foundry | - | - | - |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | Critical | 9.8 |
Microsoft Azure Kubernetes Service | - | - | - |
| CVE-2026-32183 | Windows Snipping Tool Remote Code Execution Vulnerability | Important | 7.8 |
Windows Snipping Tool | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 103 | 9 |
| Information Disclosure | 22 | 2 |
| Remote Code Execution | 22 | 9 |
| Spoofing | 13 | 2 |
| Security Feature Bypass | 11 | - |
| Denial of Service | 9 | 1 |
| Tampering | 1 | - |
Affected Products 99
| Product | CVEs | Exploited |
|---|---|---|
| Windows Ancillary Function Driver for WinSock | 8 | - |
| Windows Universal Plug and Play (UPnP) Device Host | 8 | - |
| Windows Kernel | 7 | - |
| Windows Shell | 6 | 1 |
| Desktop Window Manager | 5 | - |
| Microsoft Office Excel | 5 | - |
| Microsoft Office Word | 5 | - |
| Windows Projected File System | 5 | - |
| Windows Push Notifications | 5 | - |
| Function Discovery Service (fdwsd.dll) | 4 | - |
| Windows User Interface Core | 4 | - |
| Microsoft Brokering File System | 3 | - |
| SQL Server | 3 | - |
| Windows File Explorer | 3 | - |
| Windows SSDP Service | 3 | - |
| Windows Server Update Service | 3 | - |
| .NET | 2 | - |
| .NET Framework | 2 | - |
| Azure Monitor Agent | 2 | - |
| Microsoft Bing | 2 | - |
| Microsoft Edge (Chromium-based) | 2 | - |
| Microsoft Office SharePoint | 2 | 1 |
| Microsoft Power Apps | 2 | - |
| Microsoft PowerShell | 2 | - |
| Role: Windows Hyper-V | 2 | - |
| Universal Plug and Play (upnp.dll) | 2 | - |
| Windows Active Directory | 2 | - |
| Windows COM | 2 | - |
| Windows GDI | 2 | - |
| Windows Hello | 2 | - |
| Windows Local Security Authority Subsystem Service (LSASS) | 2 | - |
| Windows Remote Desktop Licensing Service | 2 | - |
| Windows Snipping Tool | 2 | - |
| Windows Speech Brokered Api | 2 | - |
| Windows Storage Spaces Controller | 2 | - |
| Windows TCP/IP | 2 | - |
| Windows Virtualization-Based Security (VBS) Enclave | 2 | - |
| .NET and Visual Studio | 1 | - |
| .NET, .NET Framework, Visual Studio | 1 | - |
| ASP.NET Core | 1 | - |
| Applocker Filter Driver (applockerfltr.sys) | 1 | - |
| Azure AI Foundry | 1 | - |
| Azure Custom Locations Resource Provider (RP) | 1 | - |
| Azure Databricks | 1 | - |
| Azure IOT Central | 1 | - |
| Azure Logic Apps | 1 | - |
| Azure MCP Server | 1 | - |
| Azure SRE Agent | 1 | - |
| GitHub Copilot and Visual Studio Code | 1 | - |
| M365 Copilot | 1 | - |
| Microsoft Azure Kubernetes Service | 1 | - |
| Microsoft Defender | 1 | - |
| Microsoft Dynamics 365 (Online) | 1 | - |
| Microsoft Dynamics 365 (on-premises) | 1 | - |
| Microsoft Entra ID Entitlement Management | 1 | - |
| Microsoft Graphics Component | 1 | - |
| Microsoft High Performance Compute Pack (HPC) | 1 | - |
| Microsoft Management Console | 1 | - |
| Microsoft Office | 1 | - |
| Microsoft Office PowerPoint | 1 | - |
| Microsoft Partner Center | 1 | - |
| Microsoft Purview | 1 | - |
| Microsoft Windows | 1 | - |
| Microsoft Windows Search Component | 1 | - |
| Microsoft Windows Speech | 1 | - |
| Remote Desktop Client | 1 | - |
| Windows Admin Center | 1 | - |
| Windows Advanced Rasterization Platform | 1 | - |
| Windows Biometric Service | 1 | - |
| Windows BitLocker | 1 | - |
| Windows Boot Loader | 1 | - |
| Windows Boot Manager | 1 | - |
| Windows Client Side Caching driver (csc.sys) | 1 | - |
| Windows Cloud Files Mini Filter Driver | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Container Isolation FS Filter Driver | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows Encrypting File System (EFS) | 1 | - |
| Windows HTTP.sys | 1 | - |
| Windows IKE Extension | 1 | - |
| Windows Installer | 1 | - |
| Windows Kerberos | 1 | - |
| Windows Kernel Memory | 1 | - |
| Windows LUAFV | 1 | - |
| Windows Management Services | 1 | - |
| Windows OLE | 1 | - |
| Windows Print Spooler Components | 1 | - |
| Windows RPC API | 1 | - |
| Windows Recovery Environment Agent | 1 | - |
| Windows Redirected Drive Buffering | 1 | - |
| Windows Remote Desktop | 1 | - |
| Windows Remote Procedure Call | 1 | - |
| Windows Sensor Data Service | 1 | - |
| Windows TDI Translation Driver (tdx.sys) | 1 | - |
| Windows USB Print Driver | 1 | - |
| Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) | 1 | - |
| Windows WalletService | 1 | - |
| Windows Win32K - GRFX | 1 | - |
| Windows Win32K - ICOMP | 1 | - |