Patch Tuesday Archive
Patch Tuesday June 2026
Total CVEs
219
Critical
49
Important
170
Exploited
0
Publicly Disclosed
4
All CVEs this month 219
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2026-41108 | Windows DNS Client Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Windows DNS | - | - | - |
| CVE-2026-45467 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45468 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45469 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-45475 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2026-45472 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-45471 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2026-45474 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-45479 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45486 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2026-45485 | Microsoft Office Information Disclosure Vulnerability | Important | 3.3 |
Microsoft Office | - | - | - |
| CVE-2026-45483 | Microsoft Office Project Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office Project | - | - | - |
| CVE-2026-47644 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | Critical | 7.5 |
Copilot Chat (Microsoft Edge) | - | - | - |
| CVE-2026-47655 | Microsoft Graph Information Disclosure Vulnerability | Critical | 6.5 |
Microsoft Graph | - | - | - |
| CVE-2026-47633 | Microsoft Cost Management Information Disclosure Vulnerability | Critical | 7.5 |
Cost Management Interactive Experiences | - | - | - |
| CVE-2026-32208 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Critical | 8.8 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2026-32174 | Azure Bot Service Elevation of Privilege Vulnerability | Critical | 7.7 |
Azure Bot Service | - | - | - |
| CVE-2026-45480 | Azure Active Directory Elevation of Privilege Vulnerability | Critical | 10 |
Azure Active Directory | - | - | - |
| CVE-2026-42895 | Microsoft Copilot Tampering Vulnerability | Critical | 6.5 |
Microsoft Copilot | - | - | - |
| CVE-2026-54130 | M365 Copilot Information Disclosure Vulnerability | Critical | 9.8 |
M365 Copilot | - | - | - |
| CVE-2026-47647 | Dynamics 365 Elevation of Privilege Vulnerability | Critical | 9.9 |
Microsoft Dynamics 365 | - | - | - |
| CVE-2026-48584 | Microsoft Azure Synapse Elevation of Privilege Vulnerability | Critical | 9.9 |
Azure Synapse | - | - | - |
| CVE-2026-40409 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Universal Disk Format File System Driver (UDFS) | - | - | - |
| CVE-2026-40404 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Universal Disk Format File System Driver (UDFS) | - | - | - |
| CVE-2026-33828 | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability | Critical | 7.8 |
Microsoft Azure Attestation service and Device Health Attestation Service | - | - | - |
| CVE-2026-34335 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-42902 | Microsoft PowerToys Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft PowerToys | - | - | - |
| CVE-2026-44817 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-44818 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7 |
Microsoft Office Excel | - | - | - |
| CVE-2026-44819 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2026-44820 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-44821 | Microsoft Office Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2026-44823 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-44824 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2026-45453 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45456 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-45458 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-45460 | Microsoft Office Information Disclosure Vulnerability | Critical | 4.7 |
Microsoft Office | - | - | - |
| CVE-2026-45461 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-45466 | Microsoft Word Information Disclosure Vulnerability | Important | 3.3 |
Microsoft Office Word | - | - | - |
| CVE-2026-45487 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Program Compatibility Assistant Service | - | - | - |
| CVE-2026-45490 | .NET SDK Elevation of Privilege Vulnerability | Important | 7.8 |
.NET | - | - | - |
| CVE-2026-45491 | .NET Tampering Vulnerability | Important | 5.5 |
.NET | - | - | - |
| CVE-2026-45500 | Microsoft Exchange Server Spoofing Vulnerability | Important | 6.1 |
Microsoft Exchange Server | - | - | - |
| CVE-2026-45501 | Microsoft Exchange Server Spoofing Vulnerability | Important | 6.1 |
Microsoft Exchange Server | - | - | - |
| CVE-2026-45502 | Microsoft Exchange Server Information Disclosure Vulnerability | Important | 5 |
Microsoft Exchange Server | - | - | - |
| CVE-2026-45503 | Microsoft Exchange Server Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Exchange Server | - | - | - |
| CVE-2026-45504 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Exchange Server | - | - | - |
| CVE-2026-45583 | Microsoft Exchange Server Remote Code Execution Vulnerability | Important | 8.1 |
Microsoft Exchange Server | - | - | - |
| CVE-2026-45605 | Windows Bluetooth Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Bluetooth Service | - | - | - |
| CVE-2026-45639 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important | 7.5 |
Windows RDP | - | - | - |
| CVE-2026-45640 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability | Important | 7 |
Windows Bluetooth Port Driver | - | - | - |
| CVE-2026-45606 | Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability | Important | 5.5 |
Microsoft UxTheme Library (uxtheme.dll) | - | - | - |
| CVE-2026-45607 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Hyper-V | - | - | - |
| CVE-2026-45641 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 7.8 |
Role: Windows Hyper-V | - | - | - |
| CVE-2026-45634 | Windows DHCP Client Information Disclosure Vulnerability | Important | 5.5 |
Windows DHCP Server | - | - | - |
| CVE-2026-45642 | Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability | Important | 3.9 |
Microsoft Azure Attestation service and Device Health Attestation Service | - | - | - |
| CVE-2026-45643 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2026-45645 | Microsoft Office Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office | - | - | - |
| CVE-2026-45648 | Windows Active Directory Domain Services Remote Code Execution Vulnerability | Critical | 8.8 |
Active Directory Domain Services | - | - | - |
| CVE-2026-45649 | Office for Android Spoofing Vulnerability | Important | 7.1 |
Office for Android | - | - | - |
| CVE-2026-45650 | Microsoft Bing Search Spoofing Vulnerability | Important | 4.3 |
Microsoft Bing | - | - | - |
| CVE-2026-45655 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 5.3 |
Windows BitLocker | - | - | - |
| CVE-2026-45656 | UEFI Secure Boot Security Feature Bypass Vulnerability | Important | 7.8 |
Windows UEFI | - | - | - |
| CVE-2026-45657 | Windows Kernel Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Kernel | - | - | - |
| CVE-2026-47287 | Visual Studio Code Tampering Vulnerability | Important | 6.5 |
Visual Studio Code | - | - | - |
| CVE-2026-47288 | Windows Kerberos Key Distribution Center (KDC) Remote Code Execution | Critical | 7.1 |
Windows Kerberos | - | - | - |
| CVE-2026-47289 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2026-47291 | HTTP.sys Remote Code Execution Vulnerability | Critical | 9.8 |
Windows HTTP.sys | - | - | - |
| CVE-2026-47292 | Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio Code | - | - | - |
| CVE-2026-41092 | Microsoft Kinect Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Kinect | - | - | - |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Azure Kubernetes Service | - | - | - |
| CVE-2026-47298 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47631 | Microsoft Exchange Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Exchange Server | - | - | - |
| CVE-2026-41098 | Azure Stack Edge Spoofing Vulnerability | Important | 8.4 |
Azure Stack Edge | - | - | - |
| CVE-2026-47635 | Microsoft Outlook and Word Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-47636 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47637 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47638 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47639 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47641 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45588 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-47648 | Windows Storage Elevation of Privilege Vulnerability | Important | 7 |
Windows Storage | - | - | - |
| CVE-2026-47653 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2026-47652 | Windows Hyper-V Remote Code Execution Vulnerability | Critical | 8.2 |
Windows Hyper-V | - | - | - |
| CVE-2026-47654 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-48566 | Windows DWM Core Library Information Disclosure Vulnerability | Important | 5.5 |
Windows DWM Core Library | - | - | - |
| CVE-2026-48568 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-48570 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-48573 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-48575 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-48576 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-48578 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-48583 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel | - | - | - |
| CVE-2026-49161 | Microsoft PC Manager Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft PC Manager | - | - | - |
| CVE-2026-50508 | Windows NTLM Spoofing Vulnerability | Important | 7.5 |
Windows NTLM | - | - | - |
| CVE-2026-26142 | Nuance PowerScribe Remote Code Execution Vulnerability | Critical | 9.8 |
Nuance PowerScribe | - | - | - |
| CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Defender | - | Yes | - |
| CVE-2026-50519 | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability | Important | 6.5 |
GitHub Copilot and Visual Studio Code | - | - | - |
| CVE-2026-33113 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 6.1 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-40371 | Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Dynamics 365 (on-premises) | - | - | - |
| CVE-2026-42828 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System Filter Driver | - | - | - |
| CVE-2026-42829 | Windows Administrator Protection Secure Feature Bypass Vulnerability | Important | 7.8 |
Windows Administrator Protection | - | - | - |
| CVE-2026-42835 | Microsoft Teams for Android Information Disclosure Vulnerability | Important | 8.1 |
Microsoft Teams for Android | - | - | - |
| CVE-2026-40376 | Visual Studio Code Elevation of Privilege Vulnerability | Important | 8.1 |
Visual Studio Code | - | - | - |
| CVE-2026-44822 | Microsoft Excel Information Disclosure Vulnerability | Important | 8.2 |
Microsoft Office Excel | - | - | - |
| CVE-2026-45454 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45455 | Microsoft Excel Information Disclosure Vulnerability | Important | 4.3 |
Microsoft Office Excel | - | - | - |
| CVE-2026-45457 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2026-45459 | Microsoft Excel Security Feature Bypass Vulnerability | Important | 3.3 |
Microsoft Office Excel | - | - | - |
| CVE-2026-45462 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45463 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-45464 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45465 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45476 | Microsoft Azure Network Adapter Elevation of Privilege Vulnerability | Critical | 8.2 |
Linux MANA Driver | - | - | - |
| CVE-2026-45482 | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability | Important | 8.4 |
GitHub Copilot and Visual Studio Code | - | - | - |
| CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Collaborative Translation Framework | - | Yes | - |
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | Important | 7.5 |
ASP.NET Core | - | - | - |
| CVE-2026-45592 | Windows Internet (wininet.dll) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Internet (wininet.dll) | - | - | - |
| CVE-2026-45593 | Windows SDK Elevation of Privilege Vulnerability | Important | 7.8 |
Windows SDK | - | - | - |
| CVE-2026-45594 | Windows Application Identity (AppID) Information Disclosure Vulnerability | Important | 5.5 |
Windows Application Identity (AppID) Subsystem | - | - | - |
| CVE-2026-45604 | Windows Managed Installer Information Disclosure Vulnerability | Important | 5.5 |
Windows Application Identity (AppID) Subsystem | - | - | - |
| CVE-2026-45595 | Windows Mark of the Web Security Feature Bypass Vulnerability | Important | 5.4 |
Windows Mark of the Web (MOTW) | - | - | - |
| CVE-2026-45597 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability | Important | 7 |
UI Automation Manager (uiamanager.dll) | - | - | - |
| CVE-2026-45599 | Windows UPnP Device Host Remote Code Execution Vulnerability | Important | 8.1 |
Universal Plug and Play (upnp.dll) | - | - | - |
| CVE-2026-45601 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-45598 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-45636 | Windows NTFS Remote Code Execution Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2026-45596 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-45600 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2026-45602 | Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability | Important | 9.1 |
Windows DHCP Server | - | - | - |
| CVE-2026-45635 | Windows UPnP Device Host Remote Code Execution Vulnerability | Important | 8.1 |
Universal Plug and Play (upnp.dll) | - | - | - |
| CVE-2026-45638 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-45603 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-45637 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-45608 | Windows DHCP Client Information Disclosure Vulnerability | Important | 6.8 |
Windows DHCP Client | - | - | - |
| CVE-2026-45644 | Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability | Important | 8 |
Microsoft Live Share Canvas SDK | - | - | - |
| CVE-2026-45653 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2026-45654 | Secure Boot Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Secure Boot | - | - | - |
| CVE-2026-45647 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | Important | 5.5 |
Microsoft Defender for Endpoint | - | - | - |
| CVE-2026-45658 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 6.8 |
Windows BitLocker | - | - | - |
| CVE-2026-47281 | Visual Studio Code Elevation of Privilege Vulnerability | Important | 9.6 |
Visual Studio Code | - | - | - |
| CVE-2026-47284 | Visual Studio Code Information Disclosure Vulnerability | Important | 6.5 |
Visual Studio Code | - | - | - |
| CVE-2026-47293 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | Important | 7 |
Microsoft Office Click-To-Run | - | - | - |
| CVE-2026-42910 | Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Hotpatch Monitoring Service | - | - | - |
| CVE-2026-47634 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47640 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47643 | Azure Stack Edge Remote Code Execution Vulnerability | Important | 9.8 |
Azure Stack Edge | - | - | - |
| CVE-2026-45481 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-45484 | Microsoft SharePoint Elevation of Privilege Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-47656 | Windows Boot Manager Security Feature Bypass Vulnerability | Important | 7.9 |
Windows Boot Manager | - | - | - |
| CVE-2026-48560 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-48562 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 4.6 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-48565 | Windows Narrator Braille Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Narrator Braille | - | - | - |
| CVE-2026-48569 | Visual Studio Code Security Feature Bypass Vulnerability | Important | 5.5 |
Visual Studio Code | - | - | - |
| CVE-2026-48574 | Windows Media Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Media | - | - | - |
| CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability | Important | 7.5 |
HTTP/2 | - | Yes | - |
| CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability | Important | 6.8 |
Windows BitLocker | - | Yes | - |
| CVE-2026-50511 | Microsoft PC Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft PC Manager | - | - | - |
| CVE-2026-50512 | Microsoft PC Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft PC Manager | - | - | - |
| CVE-2026-42836 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability | Important | 7 |
Function Discovery Service (fdwsd.dll) | - | - | - |
| CVE-2026-42837 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Projected File System Filter Driver | - | - | - |
| CVE-2026-42903 | Windows Kerberos Denial of Service Vulnerability | Important | 6.5 |
Windows Kerberos | - | - | - |
| CVE-2026-42904 | Windows TCP/IP Elevation of Privilege Vulnerability | Important | 9.6 |
Windows TCP/IP | - | - | - |
| CVE-2026-42905 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-42906 | Windows Shell Information Disclosure Vulnerability | Important | 5.5 |
Windows Shell | - | - | - |
| CVE-2026-42907 | Windows Shell Information Disclosure Vulnerability | Important | 6.5 |
Windows Shell | - | - | - |
| CVE-2026-42908 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important | 7.5 |
Windows RDP | - | - | - |
| CVE-2026-42980 | NT OS Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NT OS Kernel | - | - | Yes |
| CVE-2026-42909 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-42916 | NT OS Kernel Elevation of Privilege Vulnerability | Important | 7.8 |
Windows NT OS Kernel | - | - | - |
| CVE-2026-42911 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-42913 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-42912 | Windows Telephony Service Elevation of Privilege Vulnerability | Important | 7 |
Windows Telephony Service | - | - | Yes |
| CVE-2026-42914 | Windows Kerberos Denial of Service Vulnerability | Important | 5.3 |
Windows Kerberos | - | - | - |
| CVE-2026-42915 | Microsoft Windows VMSwitch Denial of Service Vulnerability | Important | 5.7 |
Windows VMSwitch | - | - | - |
| CVE-2026-42968 | Windows Telephony Server Information Disclosure Vulnerability | Important | 5.5 |
Windows Telephony Service | - | - | - |
| CVE-2026-42972 | Windows Hyper-V Information Disclosure Vulnerability | Important | 5.5 |
Role: Windows Hyper-V | - | - | - |
| CVE-2026-42969 | Windows Push Notification Information Disclosure Vulnerability | Important | 5.5 |
Windows Push Notifications | - | - | - |
| CVE-2026-42971 | Windows Push Notification Information Disclosure Vulnerability | Important | 5.5 |
Windows Push Notifications | - | - | - |
| CVE-2026-42970 | Windows Push Notification Information Disclosure Vulnerability | Important | 5.5 |
Windows Push Notifications | - | - | - |
| CVE-2026-42973 | Windows Push Notification Information Disclosure Vulnerability | Important | 5.5 |
Windows Push Notifications | - | - | - |
| CVE-2026-42984 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2026-42981 | Windows Performance Monitor Remote Code Execution Vulnerability | Important | 8.1 |
Windows Performance Monitor | - | - | - |
| CVE-2026-42974 | Windows Performance Monitor Remote Code Execution Vulnerability | Important | 8.1 |
Windows Performance Monitor | - | - | - |
| CVE-2026-42986 | Microsoft Graphics Component Elevation of Privilege Vulnerability | Important | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2026-42978 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-42977 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-42979 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-42991 | Windows Push Notifications Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Push Notifications | - | - | - |
| CVE-2026-42989 | Winlogon Elevation of Privilege Vulnerability | Important | 7.8 |
Winlogon | - | - | - |
| CVE-2026-44809 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | Yes |
| CVE-2026-44810 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | Critical | 7.8 |
Windows Cryptographic Services | - | - | - |
| CVE-2026-42992 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-44805 | Windows Network Controller (NC) Host Agent Denial of Service Vulnerability | Important | 5.5 |
Windows Network Controller (NC) Host Agent | - | - | - |
| CVE-2026-44811 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-44808 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-44807 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-44799 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-44815 | DHCP Client Service Remote Code Execution Vulnerability | Critical | 9.8 |
Windows DHCP Client | - | - | - |
| CVE-2026-42983 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-44802 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-44814 | Windows DWM Core Library Information Disclosure Vulnerability | Important | 5.5 |
Windows DWM Core Library | - | - | - |
| CVE-2026-44801 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-42985 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2026-42987 | Windows Deployment Services (WDS) Remote Code Execution | Critical | 8.1 |
Windows Deployment Services | - | - | - |
| CVE-2026-44803 | Windows Graphics Component Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Win32K - GRFX | - | - | - |
| CVE-2026-44812 | Windows Graphics Component Remote Code Execution Vulnerability | Critical | 7.8 |
Windows Win32K - GRFX | - | - | - |
| CVE-2026-42993 | Remote Desktop Client Remote Code Execution Vulnerability | Important | 7.5 |
Remote Desktop Client | - | - | - |
| CVE-2026-44813 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-44804 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 7.8 |
Windows DWM Core Library | - | - | - |
| CVE-2026-45497 | Microsoft M365 Copilot Remote Code Execution Vulnerability | Critical | 8.8 |
Microsoft Copilot | - | - | - |
| CVE-2026-42824 | M365 Copilot Information Disclosure Vulnerability | Critical | 7.5 |
M365 Copilot | - | - | - |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure HorizonDB | - | - | - |
| CVE-2026-48579 | Microsoft Exchange Online Information Disclosure Vulnerability | Critical | 7.5 |
Microsoft Exchange Online | - | - | - |
| CVE-2026-48582 | Microsoft Exchange Online Elevation of Privilege Vulnerability | Critical | 9.6 |
Microsoft Exchange Online | - | - | - |
| CVE-2026-47645 | Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability | Critical | 8.8 |
Microsoft 365 Copilot's Business Chat | - | - | - |
| CVE-2026-47646 | Dynamics 365 Customer Voice Spoofing Vulnerability | Critical | 9.3 |
Dynamics 365 Customer Voice | - | - | - |
Threat Categories 7
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 73 | 10 |
| Remote Code Execution | 55 | 29 |
| Information Disclosure | 33 | 7 |
| Spoofing | 29 | 2 |
| Security Feature Bypass | 18 | - |
| Denial of Service | 7 | - |
| Tampering | 4 | 1 |
Affected Products 94
| Product | CVEs | Exploited |
|---|---|---|
| Microsoft Office SharePoint | 21 | - |
| Microsoft Office | 14 | - |
| Remote Desktop Client | 11 | - |
| Windows DWM Core Library | 11 | - |
| Microsoft Office Excel | 8 | - |
| Windows Push Notifications | 8 | - |
| Windows Secure Boot | 8 | - |
| Microsoft Exchange Server | 7 | - |
| Windows Ancillary Function Driver for WinSock | 7 | - |
| Visual Studio Code | 6 | - |
| Microsoft Office Word | 5 | - |
| Windows Kernel | 4 | - |
| Microsoft PC Manager | 3 | - |
| Windows BitLocker | 3 | - |
| Windows Kerberos | 3 | - |
| .NET | 2 | - |
| Azure Stack Edge | 2 | - |
| GitHub Copilot and Visual Studio Code | 2 | - |
| M365 Copilot | 2 | - |
| Microsoft Azure Attestation service and Device Health Attestation Service | 2 | - |
| Microsoft Copilot | 2 | - |
| Microsoft Exchange Online | 2 | - |
| Role: Windows Hyper-V | 2 | - |
| Universal Plug and Play (upnp.dll) | 2 | - |
| Windows Application Identity (AppID) Subsystem | 2 | - |
| Windows DHCP Client | 2 | - |
| Windows DHCP Server | 2 | - |
| Windows Hyper-V | 2 | - |
| Windows NT OS Kernel | 2 | - |
| Windows Performance Monitor | 2 | - |
| Windows Projected File System Filter Driver | 2 | - |
| Windows RDP | 2 | - |
| Windows Shell | 2 | - |
| Windows Telephony Service | 2 | - |
| Windows Universal Disk Format File System Driver (UDFS) | 2 | - |
| Windows Win32K - GRFX | 2 | - |
| ASP.NET Core | 1 | - |
| Active Directory Domain Services | 1 | - |
| Azure Active Directory | 1 | - |
| Azure Bot Service | 1 | - |
| Azure HorizonDB | 1 | - |
| Azure Synapse | 1 | - |
| Copilot Chat (Microsoft Edge) | 1 | - |
| Cost Management Interactive Experiences | 1 | - |
| Dynamics 365 Customer Voice | 1 | - |
| Function Discovery Service (fdwsd.dll) | 1 | - |
| HTTP/2 | 1 | - |
| Linux MANA Driver | 1 | - |
| Microsoft 365 Copilot's Business Chat | 1 | - |
| Microsoft Azure Kubernetes Service | 1 | - |
| Microsoft Bing | 1 | - |
| Microsoft Defender | 1 | - |
| Microsoft Defender for Endpoint | 1 | - |
| Microsoft Dynamics 365 | 1 | - |
| Microsoft Dynamics 365 (on-premises) | 1 | - |
| Microsoft Edge (Chromium-based) | 1 | - |
| Microsoft Graph | 1 | - |
| Microsoft Graphics Component | 1 | - |
| Microsoft Kinect | 1 | - |
| Microsoft Live Share Canvas SDK | 1 | - |
| Microsoft Office Click-To-Run | 1 | - |
| Microsoft Office Project | 1 | - |
| Microsoft PowerToys | 1 | - |
| Microsoft Teams for Android | 1 | - |
| Microsoft UxTheme Library (uxtheme.dll) | 1 | - |
| Microsoft Windows DNS | 1 | - |
| Nuance PowerScribe | 1 | - |
| Office for Android | 1 | - |
| UI Automation Manager (uiamanager.dll) | 1 | - |
| Windows Administrator Protection | 1 | - |
| Windows Bluetooth Port Driver | 1 | - |
| Windows Bluetooth Service | 1 | - |
| Windows Boot Manager | 1 | - |
| Windows Collaborative Translation Framework | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows Cryptographic Services | 1 | - |
| Windows Deployment Services | 1 | - |
| Windows HTTP.sys | 1 | - |
| Windows Hotpatch Monitoring Service | 1 | - |
| Windows Internet (wininet.dll) | 1 | - |
| Windows Kernel-Mode Drivers | 1 | - |
| Windows Mark of the Web (MOTW) | 1 | - |
| Windows Media | 1 | - |
| Windows NTFS | 1 | - |
| Windows NTLM | 1 | - |
| Windows Narrator Braille | 1 | - |
| Windows Network Controller (NC) Host Agent | 1 | - |
| Windows Program Compatibility Assistant Service | 1 | - |
| Windows SDK | 1 | - |
| Windows Storage | 1 | - |
| Windows TCP/IP | 1 | - |
| Windows UEFI | 1 | - |
| Windows VMSwitch | 1 | - |
| Winlogon | 1 | - |