Report Name: Microsoft Patch Tuesday, June 2026
Generated: 2026-06-18 19:02:48

Vulristics Vulnerability Scores
Basic Vulnerability Scores
Products

Product NamePrevalenceUCHMLAComment
Windows Kernel0.9426Windows Kernel
Windows NTLM0.911A suite of security protocols to authenticate users' identity and protect the integrity and confidentiality of their activity
Windows TCP/IP0.911Windows component
ASP.NET Core0.811An open-source, server-side web-application framework designed for web development
Microsoft Cryptographic Services0.811he Cryptographic Services is a Microsoft Windows feature that encrypts and decrypts data on storage devices when they are accessed
Microsoft DWM Core Library0.811Windows component
Microsoft Exchange0.8347Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
Microsoft Office0.89312Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
Microsoft Windows VMSwitch0.811Windows component
Program Compatibility Assistant Service0.811The Program Compatibility Assistant (PCA) Service (PcaSvc) is a built-in Windows background feature designed to help older software and legacy games run smoothly on modern versions of the operating system. It tracks app executions and automatically applies compatibility settings when it detects known issues.
Secure Boot0.888Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
Windows Active Directory Domain Services0.811Windows component
Windows Ancillary Function Driver for WinSock0.877Windows component
Windows Application Identity (AppID)0.811Windows component
Windows BitLocker0.8213Windows component
Windows Bluetooth Port Driver0.811Windows component
Windows Bluetooth Service0.811Windows component
Windows Boot Manager0.811Windows component
Windows Collaborative Translation Framework (CTFMON)0.811Windows component
Windows Common Log File System Driver0.811Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs
Windows DHCP Client0.822Windows component
Windows DNS Client0.811Windows component
Windows DWM Core Library0.81910Windows component
Windows Device Health Attestation (DHA)0.811Windows component
Windows Dynamic Host Configuration Protocol (DHCP)0.811Windows component
Windows Function Discovery Service (fdwsd.dll)0.811Windows component
Windows Graphics Component0.822Windows component
Windows Hotpatch Monitoring Service0.811Windows component
Windows Internet (wininet.dll)0.811Windows component
Windows Kerberos0.8213Windows component
Windows Kernel-Mode Driver0.811Windows component
Windows Managed Installer0.811Windows component
Windows Mark of the Web0.811Windows component
Windows Media0.811Windows component
Windows NTFS0.811The default file system of the Windows NT family
Windows Narrator Braille0.811Windows component
Windows Network Controller (NC) Host Agent0.811Windows component
Windows Performance Monitor0.822Windows component
Windows Projected File System0.822Windows component
Windows Push Notification0.844Windows component
Windows Push Notifications0.844Windows component
Windows Remote Desktop Client0.81111Remote Desktop Protocol Client
Windows Remote Desktop Protocol0.822Windows component
Windows SDK0.811Windows component
Windows Shell0.8112Windows component
Windows Storage0.811Windows component
Windows Telephony Server0.811Windows component
Windows Telephony Service0.811Windows component
Windows UI Automation Manager (uiamanager.dll)0.811Windows component
Windows UPnP Device Host0.822Windows component
Windows Universal Disk Format File System Driver (UDFS)0.8112Windows component
.NET0.711.NET
Microsoft SharePoint0.722Microsoft SharePoint
Microsoft Excel0.688MS Office product
Microsoft Word0.644Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product.
Windows Hyper-V0.644Hardware virtualization component of the client editions of Windows NT
.NET SDK0.511.NET SDK
ARM processor0.511Processor
Azure Kubernetes Service (AKS)0.511Azure Kubernetes Service (AKS)
Azure Stack Edge0.5112Azure Stack Edge
DHCP Client Service0.511DHCP Client Service
HTTP.sys0.5112HTTP.sys
Microsoft Azure Attestation service and Device Health Attestation Service0.511Microsoft Azure Attestation service and Device Health Attestation Service
Microsoft Azure Network Adapter0.511Microsoft Azure Network Adapter
Microsoft Defender for Endpoint for Mac0.511Microsoft Defender for Endpoint for Mac
Microsoft Dynamics 365 (on-premises)0.511Microsoft Dynamics 365 (on-premises)
Microsoft Graphics Component0.511Microsoft Graphics Component
Microsoft Kinect0.511Microsoft Kinect
Microsoft Live Share Canvas SDK0.511Microsoft Live Share Canvas SDK
Microsoft Office Click-To-Run0.511Microsoft Office Click-To-Run
Microsoft Office Project Server0.511Microsoft Office Project Server
Microsoft Outlook and Word0.533Microsoft Outlook and Word
Microsoft PC Manager0.533Microsoft PC Manager
Microsoft PowerToys0.511Microsoft PowerToys
Microsoft SharePoint Server0.511819Microsoft SharePoint Server
Microsoft Teams for Android0.511Microsoft Teams for Android
Microsoft UxTheme Library (uxtheme.dll)0.511Microsoft UxTheme Library (uxtheme.dll)
Microsoft Visual Studio Code CoPilot Chat0.511Microsoft Visual Studio Code CoPilot Chat
NT OS Kernel0.5112NT OS Kernel
Nuance PowerScribe0.511Nuance PowerScribe
Office for Android0.511Office for Android
UEFI Secure Boot0.522UEFI Secure Boot
Visual Studio Code MSSQL Extension0.511Visual Studio Code MSSQL Extension
Winlogon0.511Winlogon
Visual Studio Code0.355Integrated development environment
Microsoft Bing Search0.211Microsoft Bing Search


Vulnerability Types

Vulnerability TypeCriticalityUCHMLA
Remote Code Execution1.01381655
Security Feature Bypass0.912820
Elevation of Privilege0.85144963
Information Disclosure0.8342226
Denial of Service0.7347
Memory Corruption0.511
Spoofing0.42727
Tampering0.333


Comments

SourceUCHMLA
Qualys1291444
Tenable14216
Rapid7112
ZDI145


Vulnerabilities

Urgent (0)

Critical (1)

1. Remote Code Execution - HTTP.sys (CVE-2026-47291) - Critical [690]

Description: HTTP.sys Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:DHMOSFUNK:CVE-2026-49160-CVE-2026-47291-HTTP.sys website
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514HTTP.sys
CVSS Base Score1.010CVSS Base Score is 9.8. According to Microsoft data source
EPSS Percentile0.910EPSS Probability is 0.04297, EPSS Percentile is 0.89854

Qualys: CVE-2026-47291: HTTP.sys Remote Code Execution Vulnerability An integer overflow vulnerability in Windows HTTP.sys may allow an unauthenticated attacker to execute code over a network.

Qualys: CVE-2026-47291: HTTP.sys Remote Code Execution Vulnerability This vulnerability has a CVSS:3.1 9.8 / 8.5 Policy Audit Control IDs (CIDs): 32308 Status of the ‘MaxRequestBytes (Windows HTTP.sys registry)’ Setting The following QQL will return a posture assessment for the CIDs for this Patch Tuesday: control.id: [32308] The next Patch Tuesday is scheduled for July 14, and we will provide details and patch analysis then. Until next Patch Tuesday, stay safe and secure. Be sure to subscribe to the ‘This Month in Vulnerabilities and Patches’ webinar.’

ZDI: CVE-2026-47291 - HTTP.sys Remote Code Execution Vulnerability. Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.

High (71)

2. Denial of Service - HTTP.sys (CVE-2026-49160) - High [577]

Description: HTTP.sys Denial of Service Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists1.017The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:DHMOSFUNK:CVE-2026-49160-HTTP.SYS website
Criticality of Vulnerability Type0.715Denial of Service
Vulnerable Product is Common0.514HTTP.sys
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.610EPSS Probability is 0.00969, EPSS Percentile is 0.57219

Qualys: CVE-2026-49160: HTTP.sys Denial of Service Vulnerability Uncontrolled resource consumption in HTTP/2 could allow an unauthenticated attacker to deny service over a network.

Tenable: Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)

Tenable: CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability

Tenable: CVE-2026-49160 is a denial of service (DoS) vulnerability affecting HTTP.sys. It received a CVSSv3 score of 7.5 and is rated as important. It was assessed as “Exploitation More Likely” and publicly disclosed prior to a patch being available. According to the advisory, this DoS affects HTTP/2. The advisory notes that this update adds a MaxHeadersCount registry setting which can be used to limit the number of headers included in HTTP/2 and HTTP/3 requests.

Rapid7: Every so often, a new round of denial of service vulnerabilities emerge which affect web servers implementing HTTP/2 and HTTP/3 standards. This class of vulnerabilities is likely to expand further as researchers, including the discoverers of CVE-2026-49160, use advances in LLM capability to probe not just specific software, but also the standards on which software rests. Microsoft warns that exploitation leads to uncontrolled resource consumption over a network, and expects that exploitation is more likely. The advisory credits both a third-party research firm and OpenAI’s Codex.

3. Remote Code Execution - Windows Kernel (CVE-2026-45657) - High [495]

Description: Windows Kernel Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.914Windows Kernel
CVSS Base Score1.010CVSS Base Score is 9.8. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00577, EPSS Percentile is 0.42916

Qualys: CVE-2026-45657: Windows Kernel Remote Code Execution Vulnerability A use-after-free vulnerability in the Windows Kernel could allow an unauthenticated attacker to execute code remotely.

ZDI: CVE-2026-45657 - Windows Kernel Remote Code Execution Vulnerability. This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.

4. Security Feature Bypass - Secure Boot (CVE-2026-48570) - High [494]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists0.417The existence of a private exploit is mentioned on Microsoft:PrivateExploit:PoC website
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00244, EPSS Percentile is 0.15331

5. Security Feature Bypass - Windows BitLocker (CVE-2026-50507) - High [494]

Description: Windows BitLocker Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists0.417The existence of a private exploit is mentioned on Microsoft:PrivateExploit:PoC website
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 6.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00382, EPSS Percentile is 0.29806

Qualys: CVE-2026-50507: Windows BitLocker Security Feature Bypass Vulnerability A protection mechanism failure in Windows BitLocker may allow an unauthenticated attacker to bypass a security feature with a physical attack.

Tenable: Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)

Tenable: CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability

Tenable: CVE-2026-50507 is a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.8 and is rated as important. It was publicly disclosed prior to a patch being available and assessed as “Exploitation More Likely” according to Microsoft's Exploitability Index.

Tenable: According to reports, CVE-2026-41091 is RedSun, a zero-day vulnerability disclosed by a researcher named Chaotic Eclipse or Nightmare Eclipse on April 15, 2026. This researcher has also published several additional zero-days recently, including BlueHammer (CVE-2026-33825), GreenPlasma, MiniPlasma and collaborated on Bitskrieg (CVE-2026-50507). It has since been exploited in the wild and added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (CISA KEV) catalog on May 20.

ZDI: CVE-2026-45585/CVE-2026-50507 - Windows BitLocker Security Feature Bypass Vulnerability. If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “bone shattering” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.

6. Elevation of Privilege - Windows Collaborative Translation Framework (CTFMON) (CVE-2026-45586) - High [475]

Description: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.810EPSS Probability is 0.02155, EPSS Percentile is 0.79777

Qualys: CVE-2026-45586: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability A link-following vulnerability in the Windows Collaborative Translation Framework could allow an authenticated attacker to elevate privileges locally. Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.

Tenable: CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability

Tenable: CVE-2026-45586 is an EoP vulnerability affecting Windows Collaborative Translation Framework (CTFMON), a process that supports voice and handwriting recognition. It was assigned a CVSSv3 score of 7.8 and rated as important. This EoP flaw was one of three zero-days disclosed prior to patches being made available. Successful exploitation would grant an attacker SYSTEM privileges and Microsoft has assessed this vulnerability as “Exploitation More Likely.”

7. Remote Code Execution - Windows Kernel (CVE-2026-42987) - High [471]

Description: Windows Deployment Services (WDS) Remote Code Execution

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.914Windows Kernel
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00441, EPSS Percentile is 0.35025

Qualys: CVE-2026-42987: Windows Deployment Services (WDS) Remote Code Execution Vulnerability A use-after-free in Windows Deployment Services could allow an unauthenticated attacker to execute code over a network.

8. Remote Code Execution - Windows Active Directory Domain Services (CVE-2026-45648) - High [466]

Description: Windows Active Directory Domain Services Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00547, EPSS Percentile is 0.41432

Qualys: CVE-2026-45648: Windows Active Directory Domain Services Remote Code Execution Vulnerability A stack-based buffer overflow vulnerability in Active Directory Domain Services may allow an authenticated attacker to execute code remotely.

9. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42985) - High [466]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00491, EPSS Percentile is 0.38228

Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

Tenable: While no public details have been released about these vulnerabilities as of June 9, Microsoft has assessed CVE-2026-42985 as “Exploitation More Likely” while the other CVEs were classified as either “Exploitation Unlikely” or “Exploitation Less Likely.” Patches are available for supported versions of Windows and Windows Server.

10. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-47289) - High [466]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00467, EPSS Percentile is 0.36757

Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

11. Elevation of Privilege - Windows DWM Core Library (CVE-2026-42905) - High [463]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.710EPSS Probability is 0.01628, EPSS Percentile is 0.73062

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

12. Elevation of Privilege - Microsoft SharePoint (CVE-2026-45484) - High [458]

Description: Microsoft SharePoint Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.714Microsoft SharePoint
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.710EPSS Probability is 0.01489, EPSS Percentile is 0.70704

13. Remote Code Execution - Windows Performance Monitor (CVE-2026-42974) - High [454]

Description: Windows Performance Monitor Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00524, EPSS Percentile is 0.40174

14. Remote Code Execution - Windows Performance Monitor (CVE-2026-42981) - High [454]

Description: Windows Performance Monitor Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00524, EPSS Percentile is 0.40174

15. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-47653) - High [454]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00416, EPSS Percentile is 0.33096

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

16. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-47654) - High [454]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00456, EPSS Percentile is 0.3604

Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

17. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-48563) - High [454]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00456, EPSS Percentile is 0.3604

Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

18. Remote Code Execution - Nuance PowerScribe (CVE-2026-26142) - High [452]

Description: Nuance PowerScribe Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Nuance PowerScribe
CVSS Base Score1.010CVSS Base Score is 9.8. According to Microsoft data source
EPSS Percentile0.610EPSS Probability is 0.01145, EPSS Percentile is 0.62549

Qualys: CVE-2026-26142: Nuance PowerScribe Remote Code Execution Vulnerability Deserialization of untrusted data in Nuance PowerScribe may allow an unauthenticated attacker to execute code over a network.

19. Remote Code Execution - Microsoft SharePoint (CVE-2026-45454) - High [449]

Description: Microsoft SharePoint Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.714Microsoft SharePoint
CVSS Base Score0.710CVSS Base Score is 6.5. According to Microsoft data source
EPSS Percentile0.610EPSS Probability is 0.00963, EPSS Percentile is 0.56965

20. Security Feature Bypass - Secure Boot (CVE-2026-48573) - High [448]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00828, EPSS Percentile is 0.52652

21. Security Feature Bypass - Secure Boot (CVE-2026-48576) - High [448]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00828, EPSS Percentile is 0.52652

22. Elevation of Privilege - Windows TCP/IP (CVE-2026-42904) - High [444]

Description: Windows TCP/IP Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914Windows component
CVSS Base Score1.010CVSS Base Score is 9.6. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00325, EPSS Percentile is 0.24102

23. Remote Code Execution - Microsoft Exchange (CVE-2026-45583) - High [442]

Description: Microsoft Exchange Server Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.0044, EPSS Percentile is 0.34907

24. Remote Code Execution - Microsoft Office (CVE-2026-44819) - High [442]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00358, EPSS Percentile is 0.27497

25. Remote Code Execution - Microsoft Office (CVE-2026-44824) - High [442]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00358, EPSS Percentile is 0.27497

26. Remote Code Execution - Windows Graphics Component (CVE-2026-44803) - High [442]

Description: Windows Graphics Component Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00345, EPSS Percentile is 0.26191

Qualys: CVE-2026-44803 & CVE-2026-44812: Windows Graphics Component Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Win32K – GRFX could allow an unauthenticated attacker to execute code locally.

27. Remote Code Execution - Windows Graphics Component (CVE-2026-44812) - High [442]

Description: Windows Graphics Component Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00345, EPSS Percentile is 0.26192

Qualys: CVE-2026-44803 & CVE-2026-44812: Windows Graphics Component Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Win32K – GRFX could allow an unauthenticated attacker to execute code locally.

28. Remote Code Execution - Windows Media (CVE-2026-48574) - High [442]

Description: Windows Media Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00362, EPSS Percentile is 0.27926

Qualys: CVE-2026-48574: Windows Media Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Windows Media may allow an unauthenticated attacker to execute code locally.

29. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42913) - High [442]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00432, EPSS Percentile is 0.34331

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

30. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42992) - High [442]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00362, EPSS Percentile is 0.27852

Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

31. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-44799) - High [442]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00362, EPSS Percentile is 0.27852

Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

32. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-44801) - High [442]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00362, EPSS Percentile is 0.27851

Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

33. Remote Code Execution - Windows UPnP Device Host (CVE-2026-45599) - High [442]

Description: Windows UPnP Device Host Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00403, EPSS Percentile is 0.31863

34. Remote Code Execution - Windows UPnP Device Host (CVE-2026-45635) - High [442]

Description: Windows UPnP Device Host Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00403, EPSS Percentile is 0.31863

35. Information Disclosure - Windows Remote Desktop Protocol (CVE-2026-42908) - High [436]

Description: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00693, EPSS Percentile is 0.47983

36. Information Disclosure - Windows Remote Desktop Protocol (CVE-2026-45639) - High [436]

Description: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00693, EPSS Percentile is 0.47983

37. Remote Code Execution - Microsoft Office (CVE-2026-45461) - High [430]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00318, EPSS Percentile is 0.23341

Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.

38. Remote Code Execution - Microsoft Office (CVE-2026-45463) - High [430]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00289, EPSS Percentile is 0.20432

Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.

39. Remote Code Execution - Microsoft Office (CVE-2026-45472) - High [430]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00289, EPSS Percentile is 0.20432

Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.

40. Remote Code Execution - Microsoft Office (CVE-2026-45474) - High [430]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00318, EPSS Percentile is 0.23342

Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.

41. Remote Code Execution - Microsoft Office (CVE-2026-45475) - High [430]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00298, EPSS Percentile is 0.21234

42. Remote Code Execution - Microsoft Office (CVE-2026-45486) - High [430]

Description: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 7.8. According to Vulners data source
EPSS Percentile0.210EPSS Probability is 0.00323, EPSS Percentile is 0.23813

43. Remote Code Execution - Microsoft Office (CVE-2026-45645) - High [430]

Description: Microsoft Office Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00298, EPSS Percentile is 0.21233

44. Remote Code Execution - Windows NTFS (CVE-2026-45636) - High [430]

Description: Windows NTFS Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814The default file system of the Windows NT family
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00323, EPSS Percentile is 0.23814

45. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42909) - High [430]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00317, EPSS Percentile is 0.23194

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

46. Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42993) - High [430]

Description: Remote Desktop Client Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Remote Desktop Protocol Client
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00328, EPSS Percentile is 0.24363

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability

Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.

47. Security Feature Bypass - Windows Kernel (CVE-2026-42829) - High [429]

Description: Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.914Windows Kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00267, EPSS Percentile is 0.18104

48. Remote Code Execution - Azure Stack Edge (CVE-2026-47643) - High [428]

Description: Azure Stack Edge Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Azure Stack Edge
CVSS Base Score1.010CVSS Base Score is 9.8. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00514, EPSS Percentile is 0.39565

49. Remote Code Execution - DHCP Client Service (CVE-2026-44815) - High [428]

Description: DHCP Client Service Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514DHCP Client Service
CVSS Base Score1.010CVSS Base Score is 9.8. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00565, EPSS Percentile is 0.42363

Qualys: CVE-2026-44815: DHCP Client Service Remote Code Execution Vulnerability A stack-based buffer overflow vulnerability in Windows DHCP Client could allow an unauthenticated attacker to execute code over a network.

Qualys: CVE-2026-44815: DHCP Client Service Remote Code Execution Vulnerability This vulnerability has a CVSS:3.1 9.8 / 8.5 Policy Audit Control IDs (CIDs): 1264 Status of the ‘Dynamic Host Configuration Protocol (DHCP) Client’ service The following QQL will return a posture assessment for the CIDs for this Patch Tuesday: control.id: [1264]

ZDI: CVE-2026-44815 - DHCP Client Service Remote Code Execution Vulnerability. Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.

50. Elevation of Privilege - Microsoft Exchange (CVE-2026-45504) - High [427]

Description: Microsoft Exchange Server Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00402, EPSS Percentile is 0.3175

51. Elevation of Privilege - NT OS Kernel (CVE-2026-42980) - High [425]

Description: NT OS Kernel Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514NT OS Kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.810EPSS Probability is 0.02516, EPSS Percentile is 0.82751

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

52. Elevation of Privilege - Winlogon (CVE-2026-42989) - High [425]

Description: Winlogon Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Winlogon
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.810EPSS Probability is 0.02536, EPSS Percentile is 0.8288

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

53. Information Disclosure - Windows Shell (CVE-2026-42907) - High [424]

Description: Windows Shell Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 6.5. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00657, EPSS Percentile is 0.46533

54. Remote Code Execution - Windows Kerberos (CVE-2026-47288) - High [419]

Description: Windows Kerberos Key Distribution Center (KDC) Remote Code Execution

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.1. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00314, EPSS Percentile is 0.22895

Qualys: CVE-2026-47288: Windows Kerberos Key Distribution Center (KDC) Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Kerberos may allow an authenticated attacker to execute code over an adjacent network.

55. Elevation of Privilege - Windows Narrator Braille (CVE-2026-48565) - High [416]

Description: Windows Narrator Braille Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00345, EPSS Percentile is 0.26214

56. Denial of Service - ASP.NET Core (CVE-2026-45591) - High [413]

Description: ASP.NET Core Denial of Service Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.715Denial of Service
Vulnerable Product is Common0.814An open-source, server-side web-application framework designed for web development
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00766, EPSS Percentile is 0.50637

57. Elevation of Privilege - Microsoft Graphics Component (CVE-2026-42986) - High [413]

Description: Microsoft Graphics Component Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft Graphics Component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.710EPSS Probability is 0.01628, EPSS Percentile is 0.73062

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

58. Security Feature Bypass - Secure Boot (CVE-2026-45588) - High [413]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00244, EPSS Percentile is 0.15332

59. Security Feature Bypass - Secure Boot (CVE-2026-45654) - High [413]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00248, EPSS Percentile is 0.15853

ZDI: Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls.

60. Security Feature Bypass - Secure Boot (CVE-2026-48568) - High [413]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00244, EPSS Percentile is 0.15331

61. Security Feature Bypass - Secure Boot (CVE-2026-48575) - High [413]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00244, EPSS Percentile is 0.15332

62. Security Feature Bypass - Windows Boot Manager (CVE-2026-47656) - High [413]

Description: Windows Boot Manager Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00244, EPSS Percentile is 0.15331

63. Information Disclosure - Microsoft Exchange (CVE-2026-45503) - High [412]

Description: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.810CVSS Base Score is 8.1. According to Vulners data source
EPSS Percentile0.310EPSS Probability is 0.00428, EPSS Percentile is 0.3406

64. Elevation of Privilege - Windows Kernel (CVE-2026-48583) - High [408]

Description: Windows Kernel Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914Windows Kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11743

65. Elevation of Privilege - Windows Device Health Attestation (DHA) (CVE-2026-33828) - High [404]

Description: Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00259, EPSS Percentile is 0.1701

Qualys: CVE-2026-33828: Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.

66. Elevation of Privilege - Windows Projected File System (CVE-2026-42828) - High [404]

Description: Windows Projected File System Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00299, EPSS Percentile is 0.21343

67. Elevation of Privilege - Windows Projected File System (CVE-2026-42837) - High [404]

Description: Windows Projected File System Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00299, EPSS Percentile is 0.21342

68. Elevation of Privilege - Windows Universal Disk Format File System Driver (UDFS) (CVE-2026-40404) - High [404]

Description: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00311, EPSS Percentile is 0.22578

69. Remote Code Execution - Microsoft SharePoint Server (CVE-2026-47298) - High [404]

Description: Microsoft SharePoint Server Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.810CVSS Base Score is 8.0. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00496, EPSS Percentile is 0.3851

70. Denial of Service - Windows Kerberos (CVE-2026-42903) - High [401]

Description: Windows Kerberos Denial of Service Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.715Denial of Service
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 6.5. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00727, EPSS Percentile is 0.49268

71. Security Feature Bypass - Secure Boot (CVE-2026-48578) - High [401]

Description: Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM)
CVSS Base Score0.810CVSS Base Score is 7.9. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00216, EPSS Percentile is 0.11839

72. Security Feature Bypass - Windows BitLocker (CVE-2026-45658) - High [401]

Description: Windows BitLocker Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00234, EPSS Percentile is 0.14022

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

Medium (130)

73. Information Disclosure - Microsoft Teams for Android (CVE-2026-42835) - Medium [398]

Description: Microsoft Teams for Android Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.514Microsoft Teams for Android
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.610EPSS Probability is 0.01095, EPSS Percentile is 0.61197

74. Elevation of Privilege - Windows Kernel (CVE-2026-42984) - Medium [397]

Description: Windows Kernel Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914Windows Kernel
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00205, EPSS Percentile is 0.10551

75. Elevation of Privilege - Windows Kernel (CVE-2026-45653) - Medium [397]

Description: Windows Kernel Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.914Windows Kernel
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00205, EPSS Percentile is 0.10551

76. Remote Code Execution - Microsoft Excel (CVE-2026-44817) - Medium [397]

Description: Microsoft Excel Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00291, EPSS Percentile is 0.20604

77. Remote Code Execution - Microsoft Excel (CVE-2026-44820) - Medium [397]

Description: Microsoft Excel Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00291, EPSS Percentile is 0.20605

78. Remote Code Execution - Microsoft Excel (CVE-2026-44823) - Medium [397]

Description: Microsoft Excel Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00298, EPSS Percentile is 0.21234

79. Remote Code Execution - Microsoft Excel (CVE-2026-45469) - Medium [397]

Description: Microsoft Excel Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00291, EPSS Percentile is 0.20604

80. Remote Code Execution - Microsoft Word (CVE-2026-45457) - Medium [397]

Description: Microsoft Word Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product.
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00323, EPSS Percentile is 0.23813

81. Remote Code Execution - Microsoft Word (CVE-2026-45471) - Medium [397]

Description: Microsoft Word Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product.
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00298, EPSS Percentile is 0.21233

82. Remote Code Execution - Microsoft Word (CVE-2026-45643) - Medium [397]

Description: Microsoft Word Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product.
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00323, EPSS Percentile is 0.23813

83. Remote Code Execution - Windows Hyper-V (CVE-2026-45607) - Medium [397]

Description: Windows Hyper-V Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Hardware virtualization component of the client editions of Windows NT
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00304, EPSS Percentile is 0.21885

Qualys: CVE-2026-45607, CVE-2026-47652, & CVE-2026-45641: Windows Hyper-V Remote Code Execution Vulnerability An out-of-bounds read vulnerability in Windows Hyper-V could allow an unauthenticated attacker to execute code remotely.

84. Remote Code Execution - Windows Hyper-V (CVE-2026-45641) - Medium [397]

Description: Windows Hyper-V Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Hardware virtualization component of the client editions of Windows NT
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00244, EPSS Percentile is 0.15271

Qualys: CVE-2026-45607, CVE-2026-47652, & CVE-2026-45641: Windows Hyper-V Remote Code Execution Vulnerability An out-of-bounds read vulnerability in Windows Hyper-V could allow an unauthenticated attacker to execute code remotely.

85. Remote Code Execution - Windows Hyper-V (CVE-2026-47652) - Medium [397]

Description: Windows Hyper-V Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614Hardware virtualization component of the client editions of Windows NT
CVSS Base Score0.810CVSS Base Score is 8.2. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00252, EPSS Percentile is 0.1629

Qualys: CVE-2026-45607, CVE-2026-47652, & CVE-2026-45641: Windows Hyper-V Remote Code Execution Vulnerability An out-of-bounds read vulnerability in Windows Hyper-V could allow an unauthenticated attacker to execute code remotely.

86. Elevation of Privilege - Microsoft Cryptographic Services (CVE-2026-44810) - Medium [392]

Description: Microsoft Cryptographic Services Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814he Cryptographic Services is a Microsoft Windows feature that encrypts and decrypts data on storage devices when they are accessed
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00218, EPSS Percentile is 0.12091

Qualys: CVE-2026-44810: Microsoft Cryptographic Services Elevation of Privilege Vulnerability An improper authentication vulnerability in Windows Cryptographic Services could allow an unauthorized attacker to elevate privileges locally.

87. Elevation of Privilege - Microsoft DWM Core Library (CVE-2026-45637) - Medium [392]

Description: Microsoft DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.13631

88. Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45638) - Medium [392]

Description: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.13631

89. Elevation of Privilege - Windows Bluetooth Service (CVE-2026-45605) - Medium [392]

Description: Windows Bluetooth Service Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.1363

90. Elevation of Privilege - Windows Common Log File System Driver (CVE-2026-44809) - Medium [392]

Description: Windows Common Log File System Driver Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11741

91. Elevation of Privilege - Windows DWM Core Library (CVE-2026-42983) - Medium [392]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.1362

92. Elevation of Privilege - Windows DWM Core Library (CVE-2026-44802) - Medium [392]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11742

93. Elevation of Privilege - Windows DWM Core Library (CVE-2026-44804) - Medium [392]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11741

94. Elevation of Privilege - Windows DWM Core Library (CVE-2026-44807) - Medium [392]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11742

95. Elevation of Privilege - Windows DWM Core Library (CVE-2026-44808) - Medium [392]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11743

96. Elevation of Privilege - Windows DWM Core Library (CVE-2026-44811) - Medium [392]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11742

97. Elevation of Privilege - Windows DWM Core Library (CVE-2026-44813) - Medium [392]

Description: Windows DWM Core Library Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00215, EPSS Percentile is 0.11742

98. Elevation of Privilege - Windows Hotpatch Monitoring Service (CVE-2026-42910) - Medium [392]

Description: Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.1363

99. Elevation of Privilege - Windows Internet (wininet.dll) (CVE-2026-45592) - Medium [392]

Description: Windows Internet (wininet.dll) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.1363

100. Elevation of Privilege - Windows Kernel-Mode Driver (CVE-2026-45600) - Medium [392]

Description: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.13631

101. Elevation of Privilege - Windows Push Notifications (CVE-2026-42978) - Medium [392]

Description: Windows Push Notifications Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00187, EPSS Percentile is 0.08462

102. Elevation of Privilege - Windows SDK (CVE-2026-45593) - Medium [392]

Description: Windows SDK Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0023, EPSS Percentile is 0.13631

103. Elevation of Privilege - Windows Universal Disk Format File System Driver (UDFS) (CVE-2026-40409) - Medium [392]

Description: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.0024, EPSS Percentile is 0.14804

104. Remote Code Execution - Azure Kubernetes Service (AKS) (CVE-2026-32193) - Medium [392]

Description: Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Azure Kubernetes Service (AKS)
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.003, EPSS Percentile is 0.21452

Qualys: CVE-2026-32193: Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability A path traversal vulnerability in Microsoft Azure Kubernetes Service may allow an authenticated attacker to execute code locally.

105. Remote Code Execution - Microsoft Outlook and Word (CVE-2026-45456) - Medium [392]

Description: Microsoft Outlook and Word Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Microsoft Outlook and Word
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00348, EPSS Percentile is 0.26493

Qualys: CVE-2026-45456, CVE-2026-47635, & CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability A type confusion vulnerability in Microsoft Office may allow an unauthenticated attacker to execute arbitrary code remotely.

106. Remote Code Execution - Microsoft Outlook and Word (CVE-2026-45458) - Medium [392]

Description: Microsoft Outlook and Word Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Microsoft Outlook and Word
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00348, EPSS Percentile is 0.26492

Qualys: CVE-2026-45456, CVE-2026-47635, & CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability A type confusion vulnerability in Microsoft Office may allow an unauthenticated attacker to execute arbitrary code remotely.

107. Elevation of Privilege - Microsoft Dynamics 365 (on-premises) (CVE-2026-40371) - Medium [389]

Description: Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft Dynamics 365 (on-premises)
CVSS Base Score0.910CVSS Base Score is 8.8. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00517, EPSS Percentile is 0.39761

108. Information Disclosure - Microsoft Office (CVE-2026-44821) - Medium [388]

Description: Microsoft Office Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00366, EPSS Percentile is 0.28265

109. Information Disclosure - Windows DHCP Client (CVE-2026-45608) - Medium [388]

Description: Windows DHCP Client Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 6.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00256, EPSS Percentile is 0.16682

110. Information Disclosure - Windows DWM Core Library (CVE-2026-48566) - Medium [388]

Description: Windows DWM Core Library Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00356, EPSS Percentile is 0.27271

111. Information Disclosure - Windows Push Notification (CVE-2026-42969) - Medium [388]

Description: Windows Push Notification Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00356, EPSS Percentile is 0.2727

112. Information Disclosure - Windows Push Notification (CVE-2026-42971) - Medium [388]

Description: Windows Push Notification Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00421, EPSS Percentile is 0.33517

113. Information Disclosure - Windows Telephony Server (CVE-2026-42968) - Medium [388]

Description: Windows Telephony Server Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00356, EPSS Percentile is 0.27271

114. Elevation of Privilege - Program Compatibility Assistant Service (CVE-2026-45487) - Medium [380]

Description: Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814The Program Compatibility Assistant (PCA) Service (PcaSvc) is a built-in Windows background feature designed to help older software and legacy games run smoothly on modern versions of the operating system. It tracks app executions and automatically applies compatibility settings when it detects known issues.
CVSS Base Score0.810CVSS Base Score is 7.8. According to Vulners data source
EPSS Percentile0.010EPSS Probability is 0.00148, EPSS Percentile is 0.04351

115. Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-34335) - Medium [380]

Description: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00191, EPSS Percentile is 0.0893

116. Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-42911) - Medium [380]

Description: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00191, EPSS Percentile is 0.0893

117. Elevation of Privilege - Windows Bluetooth Port Driver (CVE-2026-45640) - Medium [380]

Description: Windows Bluetooth Port Driver Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00191, EPSS Percentile is 0.0893

118. Elevation of Privilege - Windows DNS Client (CVE-2026-41108) - Medium [380]

Description: Windows DNS Client Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00237, EPSS Percentile is 0.14429

119. Elevation of Privilege - Windows Function Discovery Service (fdwsd.dll) (CVE-2026-42836) - Medium [380]

Description: Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00181, EPSS Percentile is 0.07849

120. Elevation of Privilege - Windows Push Notifications (CVE-2026-42977) - Medium [380]

Description: Windows Push Notifications Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00152, EPSS Percentile is 0.04664

121. Elevation of Privilege - Windows Push Notifications (CVE-2026-42979) - Medium [380]

Description: Windows Push Notifications Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00152, EPSS Percentile is 0.04665

122. Elevation of Privilege - Windows Push Notifications (CVE-2026-42991) - Medium [380]

Description: Windows Push Notifications Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00141, EPSS Percentile is 0.03774

123. Elevation of Privilege - Windows Storage (CVE-2026-47648) - Medium [380]

Description: Windows Storage Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00179, EPSS Percentile is 0.07604

124. Elevation of Privilege - Windows Telephony Service (CVE-2026-42912) - Medium [380]

Description: Windows Telephony Service Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00188, EPSS Percentile is 0.08583

125. Remote Code Execution - Microsoft Outlook and Word (CVE-2026-47635) - Medium [380]

Description: Microsoft Outlook and Word Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Microsoft Outlook and Word
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00264, EPSS Percentile is 0.17503

Qualys: CVE-2026-45456, CVE-2026-47635, & CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability A type confusion vulnerability in Microsoft Office may allow an unauthenticated attacker to execute arbitrary code remotely.

126. Remote Code Execution - Visual Studio Code MSSQL Extension (CVE-2026-47292) - Medium [380]

Description: Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.514Visual Studio Code MSSQL Extension
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00319, EPSS Percentile is 0.23473

127. Information Disclosure - Microsoft Excel (CVE-2026-44822) - Medium [379]

Description: Microsoft Excel Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.810CVSS Base Score is 8.2. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00417, EPSS Percentile is 0.33151

128. Denial of Service - Microsoft Windows VMSwitch (CVE-2026-42915) - Medium [377]

Description: Microsoft Windows VMSwitch Denial of Service Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.715Denial of Service
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.7. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00517, EPSS Percentile is 0.39752

129. Denial of Service - Windows Kerberos (CVE-2026-42914) - Medium [377]

Description: Windows Kerberos Denial of Service Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.715Denial of Service
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.510CVSS Base Score is 5.3. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00729, EPSS Percentile is 0.49328

130. Security Feature Bypass - Windows BitLocker (CVE-2026-45655) - Medium [377]

Description: Windows BitLocker Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.510CVSS Base Score is 5.3. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00332, EPSS Percentile is 0.24798

131. Security Feature Bypass - Windows Mark of the Web (CVE-2026-45595) - Medium [377]

Description: Windows Mark of the Web Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00321, EPSS Percentile is 0.23638

132. Information Disclosure - Microsoft Exchange (CVE-2026-45502) - Medium [376]

Description: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.510CVSS Base Score is 5.0. According to Vulners data source
EPSS Percentile0.310EPSS Probability is 0.00424, EPSS Percentile is 0.33719

133. Information Disclosure - Microsoft Office (CVE-2026-45460) - Medium [376]

Description: Microsoft Office Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.510CVSS Base Score is 4.7. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00334, EPSS Percentile is 0.25073

Qualys: CVE-2026-45460: Microsoft Office Information Disclosure Vulnerability An out-of-bounds read vulnerability in Microsoft Office could allow an unauthenticated attacker to disclose information locally.

134. Information Disclosure - Windows Application Identity (AppID) (CVE-2026-45594) - Medium [376]

Description: Windows Application Identity (AppID) Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00325, EPSS Percentile is 0.24057

135. Information Disclosure - Windows DHCP Client (CVE-2026-45634) - Medium [376]

Description: Windows DHCP Client Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00274, EPSS Percentile is 0.18976

136. Information Disclosure - Windows DWM Core Library (CVE-2026-44814) - Medium [376]

Description: Windows DWM Core Library Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00255, EPSS Percentile is 0.16668

137. Information Disclosure - Windows Managed Installer (CVE-2026-45604) - Medium [376]

Description: Windows Managed Installer Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00274, EPSS Percentile is 0.18976

138. Information Disclosure - Windows Push Notification (CVE-2026-42970) - Medium [376]

Description: Windows Push Notification Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00325, EPSS Percentile is 0.24057

139. Information Disclosure - Windows Push Notification (CVE-2026-42973) - Medium [376]

Description: Windows Push Notification Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00325, EPSS Percentile is 0.24056

140. Information Disclosure - Windows Shell (CVE-2026-42906) - Medium [376]

Description: Windows Shell Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00325, EPSS Percentile is 0.24056

141. Remote Code Execution - Microsoft Excel (CVE-2026-44818) - Medium [373]

Description: Microsoft Excel Remote Code Execution Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type1.015Remote Code Execution
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00229, EPSS Percentile is 0.13502

142. Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45596) - Medium [368]

Description: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00147, EPSS Percentile is 0.04279

143. Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45598) - Medium [368]

Description: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00147, EPSS Percentile is 0.04278

144. Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45601) - Medium [368]

Description: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00147, EPSS Percentile is 0.04278

145. Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45603) - Medium [368]

Description: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00147, EPSS Percentile is 0.04279

146. Elevation of Privilege - Windows UI Automation Manager (uiamanager.dll) (CVE-2026-45597) - Medium [368]

Description: Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00153, EPSS Percentile is 0.04767

147. Elevation of Privilege - Microsoft Live Share Canvas SDK (CVE-2026-45644) - Medium [366]

Description: Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft Live Share Canvas SDK
CVSS Base Score0.810CVSS Base Score is 8.0. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.0041, EPSS Percentile is 0.32568

148. Security Feature Bypass - Microsoft Visual Studio Code CoPilot Chat (CVE-2026-45482) - Medium [363]

Description: Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.514Microsoft Visual Studio Code CoPilot Chat
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00295, EPSS Percentile is 0.20999

149. Security Feature Bypass - UEFI Secure Boot (CVE-2026-45656) - Medium [363]

Description: UEFI Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.514UEFI Secure Boot
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00247, EPSS Percentile is 0.15745

150. Elevation of Privilege - Visual Studio Code (CVE-2026-47281) - Medium [356]

Description: Visual Studio Code Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.314Integrated development environment
CVSS Base Score1.010CVSS Base Score is 9.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00384, EPSS Percentile is 0.30076

151. Information Disclosure - Windows Hyper-V (CVE-2026-42972) - Medium [355]

Description: Windows Hyper-V Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.614Hardware virtualization component of the client editions of Windows NT
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00421, EPSS Percentile is 0.33517

152. Elevation of Privilege - Microsoft Azure Network Adapter (CVE-2026-45476) - Medium [354]

Description: Microsoft Azure Network Adapter Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft Azure Network Adapter
CVSS Base Score0.810CVSS Base Score is 8.2. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00277, EPSS Percentile is 0.19212

Qualys: CVE-2026-45476: Microsoft Azure Network Adapter Elevation of Privilege Vulnerability  A use-after-free vulnerability in the Linux MANA Driver allows an authenticated attacker to elevate local privileges.

153. Elevation of Privilege - Microsoft Kinect (CVE-2026-41092) - Medium [354]

Description: Microsoft Kinect Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft Kinect
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00267, EPSS Percentile is 0.18103

154. Elevation of Privilege - Microsoft PC Manager (CVE-2026-50511) - Medium [354]

Description: Microsoft PC Manager Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft PC Manager
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00276, EPSS Percentile is 0.19174

155. Elevation of Privilege - Microsoft PowerToys (CVE-2026-42902) - Medium [354]

Description: Microsoft PowerToys Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft PowerToys
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00267, EPSS Percentile is 0.18103

Rapid7: The Microsoft PowerToys utility provides a wide variety of useful control and configuration options for Windows power users which aren’t otherwise easily accessible. It turns out that PowerToys also offers an undocumented extra: local elevation of privilege to SYSTEM via successful exploitation of CVE-2026-42902. It is worth noting that the fix was included in PowerToys v0.99.1 on April 29, 2026, without any apparent mention in the release notes. Attackers with patch-diffing toolkits may well take note of this discrepancy.

156. Elevation of Privilege - NT OS Kernel (CVE-2026-42916) - Medium [354]

Description: NT OS Kernel Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514NT OS Kernel
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00299, EPSS Percentile is 0.21342

157. Denial of Service - Windows Network Controller (NC) Host Agent (CVE-2026-44805) - Medium [353]

Description: Windows Network Controller (NC) Host Agent Denial of Service Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.715Denial of Service
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00327, EPSS Percentile is 0.24282

158. Information Disclosure - Microsoft Office (CVE-2026-45485) - Medium [352]

Description: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.814Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer
CVSS Base Score0.310CVSS Base Score is 3.3. According to Vulners data source
EPSS Percentile0.310EPSS Probability is 0.00344, EPSS Percentile is 0.2609

159. Spoofing - Windows NTLM (CVE-2026-50508) - Medium [352]

Description: Windows NTLM Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.914A suite of security protocols to authenticate users' identity and protect the integrity and confidentiality of their activity
CVSS Base Score0.710CVSS Base Score is 6.5. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.0049, EPSS Percentile is 0.38189

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

160. Security Feature Bypass - Microsoft PC Manager (CVE-2026-49161) - Medium [351]

Description: Microsoft PC Manager Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.514Microsoft PC Manager
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00192, EPSS Percentile is 0.08995

161. Elevation of Privilege - Visual Studio Code (CVE-2026-40376) - Medium [344]

Description: Visual Studio Code Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.314Integrated development environment
CVSS Base Score0.810CVSS Base Score is 7.5. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.006, EPSS Percentile is 0.4399

162. Elevation of Privilege - .NET SDK (CVE-2026-45490) - Medium [342]

Description: .NET SDK Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514.NET SDK
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00219, EPSS Percentile is 0.12171

163. Elevation of Privilege - Microsoft PC Manager (CVE-2026-50512) - Medium [342]

Description: Microsoft PC Manager Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft PC Manager
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00207, EPSS Percentile is 0.10783

164. Security Feature Bypass - UEFI Secure Boot (CVE-2026-8863) - Medium [339]

Description: UEFI Secure Boot Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.514UEFI Secure Boot
CVSS Base Score0.810CVSS Base Score is 7.8. According to Microsoft data source
EPSS Percentile0.010EPSS Probability is 0.00078, EPSS Percentile is 0.00193

Tenable: Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.

165. Elevation of Privilege - Microsoft Office Click-To-Run (CVE-2026-47293) - Medium [330]

Description: Microsoft Office Click-To-Run Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft Office Click-To-Run
CVSS Base Score0.710CVSS Base Score is 7.0. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00196, EPSS Percentile is 0.09429

166. Information Disclosure - Visual Studio Code (CVE-2026-47284) - Medium [329]

Description: Visual Studio Code Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.314Integrated development environment
CVSS Base Score0.710CVSS Base Score is 6.5. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00598, EPSS Percentile is 0.43915

167. Spoofing - Microsoft Exchange (CVE-2026-47631) - Medium [323]

Description: Microsoft Exchange Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.810CVSS Base Score is 8.1. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00244, EPSS Percentile is 0.15314

168. Security Feature Bypass - Microsoft Excel (CVE-2026-45459) - Medium [320]

Description: Microsoft Excel Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.310CVSS Base Score is 3.3. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00322, EPSS Percentile is 0.23787

169. Elevation of Privilege - Microsoft Defender for Endpoint for Mac (CVE-2026-45647) - Medium [318]

Description: Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8515Elevation of Privilege
Vulnerable Product is Common0.514Microsoft Defender for Endpoint for Mac
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.110EPSS Probability is 0.00197, EPSS Percentile is 0.09527

170. Security Feature Bypass - Visual Studio Code (CVE-2026-48569) - Medium [317]

Description: Visual Studio Code Security Feature Bypass Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.915Security Feature Bypass
Vulnerable Product is Common0.314Integrated development environment
CVSS Base Score0.710CVSS Base Score is 7.1. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00287, EPSS Percentile is 0.20185

171. Tampering - Windows Dynamic Host Configuration Protocol (DHCP) (CVE-2026-45602) - Medium [317]

Description: Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.315Tampering
Vulnerable Product is Common0.814Windows component
CVSS Base Score0.910CVSS Base Score is 9.1. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00262, EPSS Percentile is 0.17318

172. Denial of Service - Microsoft UxTheme Library (uxtheme.dll) (CVE-2026-45606) - Medium [315]

Description: Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.715Denial of Service
Vulnerable Product is Common0.514Microsoft UxTheme Library (uxtheme.dll)
CVSS Base Score0.610CVSS Base Score is 5.5. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00351, EPSS Percentile is 0.26797

173. Memory Corruption - ARM processor (CVE-2025-10263) - Medium [315]

Description: Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.515Memory Corruption
Vulnerable Product is Common0.514Processor
CVSS Base Score0.910CVSS Base Score is 9.3. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.0039, EPSS Percentile is 0.30637

Qualys: CVE-2025-10263: ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] An attacker could exploit the vulnerability by triggering a specific timing condition during a memory permission change, causing a memory write to be applied using outdated permissions. Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.

Tenable: Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.

174. Spoofing - Microsoft Exchange (CVE-2026-45500) - Medium [311]

Description: Microsoft Exchange Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.610CVSS Base Score is 6.1. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00382, EPSS Percentile is 0.29886

175. Spoofing - Microsoft Exchange (CVE-2026-45501) - Medium [311]

Description: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.814Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft
CVSS Base Score0.710CVSS Base Score is 6.5. According to Vulners data source
EPSS Percentile0.210EPSS Probability is 0.00297, EPSS Percentile is 0.21125

176. Spoofing - Azure Stack Edge (CVE-2026-41098) - Medium [309]

Description: Azure Stack Edge Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Azure Stack Edge
CVSS Base Score0.810CVSS Base Score is 8.4. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00744, EPSS Percentile is 0.49856

177. Information Disclosure - Microsoft Excel (CVE-2026-45455) - Medium [307]

Description: Microsoft Excel Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.614MS Office product
CVSS Base Score0.310CVSS Base Score is 3.3. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00297, EPSS Percentile is 0.2121

178. Information Disclosure - Microsoft Word (CVE-2026-45466) - Medium [307]

Description: Microsoft Word Information Disclosure Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.8315Information Disclosure
Vulnerable Product is Common0.614Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product.
CVSS Base Score0.310CVSS Base Score is 3.3. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00329, EPSS Percentile is 0.2453

179. Spoofing - Microsoft SharePoint Server (CVE-2026-45481) - Medium [285]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.710CVSS Base Score is 7.3. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00482, EPSS Percentile is 0.3769

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

180. Spoofing - Microsoft SharePoint Server (CVE-2026-47634) - Medium [273]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.710CVSS Base Score is 7.3. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00392, EPSS Percentile is 0.30843

Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.

181. Spoofing - Microsoft SharePoint Server (CVE-2026-48560) - Medium [273]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.510EPSS Probability is 0.00735, EPSS Percentile is 0.49565

182. Spoofing - Office for Android (CVE-2026-45649) - Medium [273]

Description: Office for Android Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Office for Android
CVSS Base Score0.710CVSS Base Score is 7.1. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00336, EPSS Percentile is 0.25214

183. Tampering - .NET (CVE-2026-45491) - Medium [265]

Description: Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.315Tampering
Vulnerable Product is Common0.714.NET
CVSS Base Score0.610CVSS Base Score is 6.2. According to Vulners data source
EPSS Percentile0.210EPSS Probability is 0.00301, EPSS Percentile is 0.21555

184. Spoofing - Microsoft SharePoint Server (CVE-2026-33113) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00409, EPSS Percentile is 0.32445

185. Spoofing - Microsoft SharePoint Server (CVE-2026-45453) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.004, EPSS Percentile is 0.31613

186. Spoofing - Microsoft SharePoint Server (CVE-2026-45462) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31212

187. Spoofing - Microsoft SharePoint Server (CVE-2026-45464) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.004, EPSS Percentile is 0.31613

188. Spoofing - Microsoft SharePoint Server (CVE-2026-45465) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.004, EPSS Percentile is 0.31614

189. Spoofing - Microsoft SharePoint Server (CVE-2026-45467) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31212

190. Spoofing - Microsoft SharePoint Server (CVE-2026-45468) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31212

191. Spoofing - Microsoft SharePoint Server (CVE-2026-45479) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31214

192. Spoofing - Microsoft SharePoint Server (CVE-2026-47636) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.004, EPSS Percentile is 0.31614

193. Spoofing - Microsoft SharePoint Server (CVE-2026-47637) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31213

194. Spoofing - Microsoft SharePoint Server (CVE-2026-47638) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31213

195. Spoofing - Microsoft SharePoint Server (CVE-2026-47639) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 5.4. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.004, EPSS Percentile is 0.31614

196. Spoofing - Microsoft SharePoint Server (CVE-2026-47640) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31213

197. Spoofing - Microsoft SharePoint Server (CVE-2026-47641) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31214

198. Spoofing - Microsoft SharePoint Server (CVE-2026-48562) - Medium [250]

Description: Microsoft SharePoint Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft SharePoint Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.310EPSS Probability is 0.00396, EPSS Percentile is 0.31214

199. Spoofing - Microsoft Office Project Server (CVE-2026-45483) - Medium [238]

Description: Microsoft Office Project Server Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft Office Project Server
CVSS Base Score0.510CVSS Base Score is 4.6. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00272, EPSS Percentile is 0.18743

200. Tampering - Visual Studio Code (CVE-2026-47287) - Medium [234]

Description: Visual Studio Code Tampering Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.315Tampering
Vulnerable Product is Common0.314Integrated development environment
CVSS Base Score0.710CVSS Base Score is 6.5. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00509, EPSS Percentile is 0.3927

201. Spoofing - Microsoft Azure Attestation service and Device Health Attestation Service (CVE-2026-45642) - Medium [226]

Description: Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.514Microsoft Azure Attestation service and Device Health Attestation Service
CVSS Base Score0.410CVSS Base Score is 3.9. According to Microsoft data source
EPSS Percentile0.210EPSS Probability is 0.00257, EPSS Percentile is 0.16833

202. Spoofing - Microsoft Bing Search (CVE-2026-45650) - Medium [200]

Description: Microsoft Bing Search Spoofing Vulnerability

ComponentValueWeightComment
Exploited in the Wild018Exploitation in the wild is NOT mentioned in available Data Sources
Exploit Exists017The existence of publicly available or private exploit is NOT mentioned in available Data Sources
Criticality of Vulnerability Type0.415Spoofing
Vulnerable Product is Common0.214Microsoft Bing Search
CVSS Base Score0.410CVSS Base Score is 4.3. According to Microsoft data source
EPSS Percentile0.410EPSS Probability is 0.00486, EPSS Percentile is 0.37911

Low (0)

Exploitation in the wild detected (0)

Public exploit exists, but exploitation in the wild is NOT detected (2)

Remote Code Execution (1)

Denial of Service (1)

Other Vulnerabilities (200)

Remote Code Execution (54)

Security Feature Bypass (20)

Elevation of Privilege (63)

Information Disclosure (26)

Denial of Service (6)

Spoofing (27)

Tampering (3)

Memory Corruption (1)