Report Name: Microsoft Patch Tuesday, June 2026Generated: 2026-06-18 19:02:48
| Product Name | Prevalence | U | C | H | M | L | A | Comment |
|---|---|---|---|---|---|---|---|---|
| Windows Kernel | 0.9 | 4 | 2 | 6 | Windows Kernel | |||
| Windows NTLM | 0.9 | 1 | 1 | A suite of security protocols to authenticate users' identity and protect the integrity and confidentiality of their activity | ||||
| Windows TCP/IP | 0.9 | 1 | 1 | Windows component | ||||
| ASP.NET Core | 0.8 | 1 | 1 | An open-source, server-side web-application framework designed for web development | ||||
| Microsoft Cryptographic Services | 0.8 | 1 | 1 | he Cryptographic Services is a Microsoft Windows feature that encrypts and decrypts data on storage devices when they are accessed | ||||
| Microsoft DWM Core Library | 0.8 | 1 | 1 | Windows component | ||||
| Microsoft Exchange | 0.8 | 3 | 4 | 7 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |||
| Microsoft Office | 0.8 | 9 | 3 | 12 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |||
| Microsoft Windows VMSwitch | 0.8 | 1 | 1 | Windows component | ||||
| Program Compatibility Assistant Service | 0.8 | 1 | 1 | The Program Compatibility Assistant (PCA) Service (PcaSvc) is a built-in Windows background feature designed to help older software and legacy games run smoothly on modern versions of the operating system. It tracks app executions and automatically applies compatibility settings when it detects known issues. | ||||
| Secure Boot | 0.8 | 8 | 8 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | ||||
| Windows Active Directory Domain Services | 0.8 | 1 | 1 | Windows component | ||||
| Windows Ancillary Function Driver for WinSock | 0.8 | 7 | 7 | Windows component | ||||
| Windows Application Identity (AppID) | 0.8 | 1 | 1 | Windows component | ||||
| Windows BitLocker | 0.8 | 2 | 1 | 3 | Windows component | |||
| Windows Bluetooth Port Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows Bluetooth Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Boot Manager | 0.8 | 1 | 1 | Windows component | ||||
| Windows Collaborative Translation Framework (CTFMON) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Common Log File System Driver | 0.8 | 1 | 1 | Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs | ||||
| Windows DHCP Client | 0.8 | 2 | 2 | Windows component | ||||
| Windows DNS Client | 0.8 | 1 | 1 | Windows component | ||||
| Windows DWM Core Library | 0.8 | 1 | 9 | 10 | Windows component | |||
| Windows Device Health Attestation (DHA) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Dynamic Host Configuration Protocol (DHCP) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Function Discovery Service (fdwsd.dll) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Graphics Component | 0.8 | 2 | 2 | Windows component | ||||
| Windows Hotpatch Monitoring Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows Internet (wininet.dll) | 0.8 | 1 | 1 | Windows component | ||||
| Windows Kerberos | 0.8 | 2 | 1 | 3 | Windows component | |||
| Windows Kernel-Mode Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows Managed Installer | 0.8 | 1 | 1 | Windows component | ||||
| Windows Mark of the Web | 0.8 | 1 | 1 | Windows component | ||||
| Windows Media | 0.8 | 1 | 1 | Windows component | ||||
| Windows NTFS | 0.8 | 1 | 1 | The default file system of the Windows NT family | ||||
| Windows Narrator Braille | 0.8 | 1 | 1 | Windows component | ||||
| Windows Network Controller (NC) Host Agent | 0.8 | 1 | 1 | Windows component | ||||
| Windows Performance Monitor | 0.8 | 2 | 2 | Windows component | ||||
| Windows Projected File System | 0.8 | 2 | 2 | Windows component | ||||
| Windows Push Notification | 0.8 | 4 | 4 | Windows component | ||||
| Windows Push Notifications | 0.8 | 4 | 4 | Windows component | ||||
| Windows Remote Desktop Client | 0.8 | 11 | 11 | Remote Desktop Protocol Client | ||||
| Windows Remote Desktop Protocol | 0.8 | 2 | 2 | Windows component | ||||
| Windows SDK | 0.8 | 1 | 1 | Windows component | ||||
| Windows Shell | 0.8 | 1 | 1 | 2 | Windows component | |||
| Windows Storage | 0.8 | 1 | 1 | Windows component | ||||
| Windows Telephony Server | 0.8 | 1 | 1 | Windows component | ||||
| Windows Telephony Service | 0.8 | 1 | 1 | Windows component | ||||
| Windows UI Automation Manager (uiamanager.dll) | 0.8 | 1 | 1 | Windows component | ||||
| Windows UPnP Device Host | 0.8 | 2 | 2 | Windows component | ||||
| Windows Universal Disk Format File System Driver (UDFS) | 0.8 | 1 | 1 | 2 | Windows component | |||
| .NET | 0.7 | 1 | 1 | .NET | ||||
| Microsoft SharePoint | 0.7 | 2 | 2 | Microsoft SharePoint | ||||
| Microsoft Excel | 0.6 | 8 | 8 | MS Office product | ||||
| Microsoft Word | 0.6 | 4 | 4 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | ||||
| Windows Hyper-V | 0.6 | 4 | 4 | Hardware virtualization component of the client editions of Windows NT | ||||
| .NET SDK | 0.5 | 1 | 1 | .NET SDK | ||||
| ARM processor | 0.5 | 1 | 1 | Processor | ||||
| Azure Kubernetes Service (AKS) | 0.5 | 1 | 1 | Azure Kubernetes Service (AKS) | ||||
| Azure Stack Edge | 0.5 | 1 | 1 | 2 | Azure Stack Edge | |||
| DHCP Client Service | 0.5 | 1 | 1 | DHCP Client Service | ||||
| HTTP.sys | 0.5 | 1 | 1 | 2 | HTTP.sys | |||
| Microsoft Azure Attestation service and Device Health Attestation Service | 0.5 | 1 | 1 | Microsoft Azure Attestation service and Device Health Attestation Service | ||||
| Microsoft Azure Network Adapter | 0.5 | 1 | 1 | Microsoft Azure Network Adapter | ||||
| Microsoft Defender for Endpoint for Mac | 0.5 | 1 | 1 | Microsoft Defender for Endpoint for Mac | ||||
| Microsoft Dynamics 365 (on-premises) | 0.5 | 1 | 1 | Microsoft Dynamics 365 (on-premises) | ||||
| Microsoft Graphics Component | 0.5 | 1 | 1 | Microsoft Graphics Component | ||||
| Microsoft Kinect | 0.5 | 1 | 1 | Microsoft Kinect | ||||
| Microsoft Live Share Canvas SDK | 0.5 | 1 | 1 | Microsoft Live Share Canvas SDK | ||||
| Microsoft Office Click-To-Run | 0.5 | 1 | 1 | Microsoft Office Click-To-Run | ||||
| Microsoft Office Project Server | 0.5 | 1 | 1 | Microsoft Office Project Server | ||||
| Microsoft Outlook and Word | 0.5 | 3 | 3 | Microsoft Outlook and Word | ||||
| Microsoft PC Manager | 0.5 | 3 | 3 | Microsoft PC Manager | ||||
| Microsoft PowerToys | 0.5 | 1 | 1 | Microsoft PowerToys | ||||
| Microsoft SharePoint Server | 0.5 | 1 | 18 | 19 | Microsoft SharePoint Server | |||
| Microsoft Teams for Android | 0.5 | 1 | 1 | Microsoft Teams for Android | ||||
| Microsoft UxTheme Library (uxtheme.dll) | 0.5 | 1 | 1 | Microsoft UxTheme Library (uxtheme.dll) | ||||
| Microsoft Visual Studio Code CoPilot Chat | 0.5 | 1 | 1 | Microsoft Visual Studio Code CoPilot Chat | ||||
| NT OS Kernel | 0.5 | 1 | 1 | 2 | NT OS Kernel | |||
| Nuance PowerScribe | 0.5 | 1 | 1 | Nuance PowerScribe | ||||
| Office for Android | 0.5 | 1 | 1 | Office for Android | ||||
| UEFI Secure Boot | 0.5 | 2 | 2 | UEFI Secure Boot | ||||
| Visual Studio Code MSSQL Extension | 0.5 | 1 | 1 | Visual Studio Code MSSQL Extension | ||||
| Winlogon | 0.5 | 1 | 1 | Winlogon | ||||
| Visual Studio Code | 0.3 | 5 | 5 | Integrated development environment | ||||
| Microsoft Bing Search | 0.2 | 1 | 1 | Microsoft Bing Search |
| Vulnerability Type | Criticality | U | C | H | M | L | A |
|---|---|---|---|---|---|---|---|
| Remote Code Execution | 1.0 | 1 | 38 | 16 | 55 | ||
| Security Feature Bypass | 0.9 | 12 | 8 | 20 | |||
| Elevation of Privilege | 0.85 | 14 | 49 | 63 | |||
| Information Disclosure | 0.83 | 4 | 22 | 26 | |||
| Denial of Service | 0.7 | 3 | 4 | 7 | |||
| Memory Corruption | 0.5 | 1 | 1 | ||||
| Spoofing | 0.4 | 27 | 27 | ||||
| Tampering | 0.3 | 3 | 3 |
| Source | U | C | H | M | L | A |
|---|---|---|---|---|---|---|
| Qualys | 1 | 29 | 14 | 44 | ||
| Tenable | 14 | 2 | 16 | |||
| Rapid7 | 1 | 1 | 2 | |||
| ZDI | 1 | 4 | 5 |
1.
Remote Code Execution - HTTP.sys (CVE-2026-47291) - Critical [690]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:DHMOSFUNK:CVE-2026-49160-CVE-2026-47291-HTTP.sys website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | HTTP.sys | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.04297, EPSS Percentile is 0.89854 |
Qualys: CVE-2026-47291: HTTP.sys Remote Code Execution Vulnerability An integer overflow vulnerability in Windows HTTP.sys may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-47291: HTTP.sys Remote Code Execution Vulnerability This vulnerability has a CVSS:3.1 9.8 / 8.5 Policy Audit Control IDs (CIDs): 32308 Status of the ‘MaxRequestBytes (Windows HTTP.sys registry)’ Setting The following QQL will return a posture assessment for the CIDs for this Patch Tuesday: control.id: [32308] The next Patch Tuesday is scheduled for July 14, and we will provide details and patch analysis then. Until next Patch Tuesday, stay safe and secure. Be sure to subscribe to the ‘This Month in Vulnerabilities and Patches’ webinar.’
ZDI: CVE-2026-47291 - HTTP.sys Remote Code Execution Vulnerability. Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.
2.
Denial of Service - HTTP.sys (CVE-2026-49160) - High [577]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:DHMOSFUNK:CVE-2026-49160-HTTP.SYS website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | HTTP.sys | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.6 | 10 | EPSS Probability is 0.00969, EPSS Percentile is 0.57219 |
Qualys: CVE-2026-49160: HTTP.sys Denial of Service Vulnerability Uncontrolled resource consumption in HTTP/2 could allow an unauthenticated attacker to deny service over a network.
Tenable: Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
Tenable: CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability
Tenable: CVE-2026-49160 is a denial of service (DoS) vulnerability affecting HTTP.sys. It received a CVSSv3 score of 7.5 and is rated as important. It was assessed as “Exploitation More Likely” and publicly disclosed prior to a patch being available. According to the advisory, this DoS affects HTTP/2. The advisory notes that this update adds a MaxHeadersCount registry setting which can be used to limit the number of headers included in HTTP/2 and HTTP/3 requests.
Rapid7: Every so often, a new round of denial of service vulnerabilities emerge which affect web servers implementing HTTP/2 and HTTP/3 standards. This class of vulnerabilities is likely to expand further as researchers, including the discoverers of CVE-2026-49160, use advances in LLM capability to probe not just specific software, but also the standards on which software rests. Microsoft warns that exploitation leads to uncontrolled resource consumption over a network, and expects that exploitation is more likely. The advisory credits both a third-party research firm and OpenAI’s Codex.
3.
Remote Code Execution - Windows Kernel (CVE-2026-45657) - High [495]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00577, EPSS Percentile is 0.42916 |
Qualys: CVE-2026-45657: Windows Kernel Remote Code Execution Vulnerability A use-after-free vulnerability in the Windows Kernel could allow an unauthenticated attacker to execute code remotely.
ZDI: CVE-2026-45657 - Windows Kernel Remote Code Execution Vulnerability. This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.
4.
Security Feature Bypass - Secure Boot (CVE-2026-48570) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.4 | 17 | The existence of a private exploit is mentioned on Microsoft:PrivateExploit:PoC website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15331 |
5.
Security Feature Bypass - Windows BitLocker (CVE-2026-50507) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.4 | 17 | The existence of a private exploit is mentioned on Microsoft:PrivateExploit:PoC website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00382, EPSS Percentile is 0.29806 |
Qualys: CVE-2026-50507: Windows BitLocker Security Feature Bypass Vulnerability A protection mechanism failure in Windows BitLocker may allow an unauthenticated attacker to bypass a security feature with a physical attack.
Tenable: Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
Tenable: CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability
Tenable: CVE-2026-50507 is a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.8 and is rated as important. It was publicly disclosed prior to a patch being available and assessed as “Exploitation More Likely” according to Microsoft's Exploitability Index.
Tenable: According to reports, CVE-2026-41091 is RedSun, a zero-day vulnerability disclosed by a researcher named Chaotic Eclipse or Nightmare Eclipse on April 15, 2026. This researcher has also published several additional zero-days recently, including BlueHammer (CVE-2026-33825), GreenPlasma, MiniPlasma and collaborated on Bitskrieg (CVE-2026-50507). It has since been exploited in the wild and added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (CISA KEV) catalog on May 20.
ZDI: CVE-2026-45585/CVE-2026-50507 - Windows BitLocker Security Feature Bypass Vulnerability. If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “bone shattering” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.
6.
Elevation of Privilege - Windows Collaborative Translation Framework (CTFMON) (CVE-2026-45586) - High [475]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.8 | 10 | EPSS Probability is 0.02155, EPSS Percentile is 0.79777 |
Qualys: CVE-2026-45586: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability A link-following vulnerability in the Windows Collaborative Translation Framework could allow an authenticated attacker to elevate privileges locally. Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.
Tenable: CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Tenable: CVE-2026-45586 is an EoP vulnerability affecting Windows Collaborative Translation Framework (CTFMON), a process that supports voice and handwriting recognition. It was assigned a CVSSv3 score of 7.8 and rated as important. This EoP flaw was one of three zero-days disclosed prior to patches being made available. Successful exploitation would grant an attacker SYSTEM privileges and Microsoft has assessed this vulnerability as “Exploitation More Likely.”
7.
Remote Code Execution - Windows Kernel (CVE-2026-42987) - High [471]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.35025 |
Qualys: CVE-2026-42987: Windows Deployment Services (WDS) Remote Code Execution Vulnerability A use-after-free in Windows Deployment Services could allow an unauthenticated attacker to execute code over a network.
8.
Remote Code Execution - Windows Active Directory Domain Services (CVE-2026-45648) - High [466]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00547, EPSS Percentile is 0.41432 |
Qualys: CVE-2026-45648: Windows Active Directory Domain Services Remote Code Execution Vulnerability A stack-based buffer overflow vulnerability in Active Directory Domain Services may allow an authenticated attacker to execute code remotely.
9.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42985) - High [466]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.38228 |
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
Tenable: While no public details have been released about these vulnerabilities as of June 9, Microsoft has assessed CVE-2026-42985 as “Exploitation More Likely” while the other CVEs were classified as either “Exploitation Unlikely” or “Exploitation Less Likely.” Patches are available for supported versions of Windows and Windows Server.
10.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-47289) - High [466]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00467, EPSS Percentile is 0.36757 |
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
11.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-42905) - High [463]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.7 | 10 | EPSS Probability is 0.01628, EPSS Percentile is 0.73062 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
12.
Elevation of Privilege - Microsoft SharePoint (CVE-2026-45484) - High [458]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | Microsoft SharePoint | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.7 | 10 | EPSS Probability is 0.01489, EPSS Percentile is 0.70704 |
13.
Remote Code Execution - Windows Performance Monitor (CVE-2026-42974) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00524, EPSS Percentile is 0.40174 |
14.
Remote Code Execution - Windows Performance Monitor (CVE-2026-42981) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00524, EPSS Percentile is 0.40174 |
15.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-47653) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00416, EPSS Percentile is 0.33096 |
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
16.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-47654) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00456, EPSS Percentile is 0.3604 |
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
17.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-48563) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00456, EPSS Percentile is 0.3604 |
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
18.
Remote Code Execution - Nuance PowerScribe (CVE-2026-26142) - High [452]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Nuance PowerScribe | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0.6 | 10 | EPSS Probability is 0.01145, EPSS Percentile is 0.62549 |
Qualys: CVE-2026-26142: Nuance PowerScribe Remote Code Execution Vulnerability Deserialization of untrusted data in Nuance PowerScribe may allow an unauthenticated attacker to execute code over a network.
19.
Remote Code Execution - Microsoft SharePoint (CVE-2026-45454) - High [449]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Microsoft SharePoint | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0.6 | 10 | EPSS Probability is 0.00963, EPSS Percentile is 0.56965 |
20.
Security Feature Bypass - Secure Boot (CVE-2026-48573) - High [448]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00828, EPSS Percentile is 0.52652 |
21.
Security Feature Bypass - Secure Boot (CVE-2026-48576) - High [448]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00828, EPSS Percentile is 0.52652 |
22.
Elevation of Privilege - Windows TCP/IP (CVE-2026-42904) - High [444]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.24102 |
23.
Remote Code Execution - Microsoft Exchange (CVE-2026-45583) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.0044, EPSS Percentile is 0.34907 |
24.
Remote Code Execution - Microsoft Office (CVE-2026-44819) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.27497 |
25.
Remote Code Execution - Microsoft Office (CVE-2026-44824) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.27497 |
26.
Remote Code Execution - Windows Graphics Component (CVE-2026-44803) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.26191 |
Qualys: CVE-2026-44803 & CVE-2026-44812: Windows Graphics Component Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Win32K – GRFX could allow an unauthenticated attacker to execute code locally.
27.
Remote Code Execution - Windows Graphics Component (CVE-2026-44812) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.26192 |
Qualys: CVE-2026-44803 & CVE-2026-44812: Windows Graphics Component Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Win32K – GRFX could allow an unauthenticated attacker to execute code locally.
28.
Remote Code Execution - Windows Media (CVE-2026-48574) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00362, EPSS Percentile is 0.27926 |
Qualys: CVE-2026-48574: Windows Media Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Windows Media may allow an unauthenticated attacker to execute code locally.
29.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42913) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.34331 |
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
30.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42992) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00362, EPSS Percentile is 0.27852 |
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
31.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-44799) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00362, EPSS Percentile is 0.27852 |
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
32.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-44801) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00362, EPSS Percentile is 0.27851 |
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
33.
Remote Code Execution - Windows UPnP Device Host (CVE-2026-45599) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00403, EPSS Percentile is 0.31863 |
34.
Remote Code Execution - Windows UPnP Device Host (CVE-2026-45635) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00403, EPSS Percentile is 0.31863 |
35.
Information Disclosure - Windows Remote Desktop Protocol (CVE-2026-42908) - High [436]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00693, EPSS Percentile is 0.47983 |
36.
Information Disclosure - Windows Remote Desktop Protocol (CVE-2026-45639) - High [436]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00693, EPSS Percentile is 0.47983 |
37.
Remote Code Execution - Microsoft Office (CVE-2026-45461) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.23341 |
Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.
38.
Remote Code Execution - Microsoft Office (CVE-2026-45463) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.20432 |
Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.
39.
Remote Code Execution - Microsoft Office (CVE-2026-45472) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.20432 |
Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.
40.
Remote Code Execution - Microsoft Office (CVE-2026-45474) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.23342 |
Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.
41.
Remote Code Execution - Microsoft Office (CVE-2026-45475) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.21234 |
42.
Remote Code Execution - Microsoft Office (CVE-2026-45486) - High [430]
Description: Untrusted pointer dereference in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.23813 |
43.
Remote Code Execution - Microsoft Office (CVE-2026-45645) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.21233 |
44.
Remote Code Execution - Windows NTFS (CVE-2026-45636) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.23814 |
45.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42909) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.23194 |
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
46.
Remote Code Execution - Windows Remote Desktop Client (CVE-2026-42993) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Desktop Protocol Client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.24363 |
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
47.
Security Feature Bypass - Windows Kernel (CVE-2026-42829) - High [429]
Description: Improper access control in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18104 |
48.
Remote Code Execution - Azure Stack Edge (CVE-2026-47643) - High [428]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Azure Stack Edge | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.39565 |
49.
Remote Code Execution - DHCP Client Service (CVE-2026-44815) - High [428]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | DHCP Client Service | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00565, EPSS Percentile is 0.42363 |
Qualys: CVE-2026-44815: DHCP Client Service Remote Code Execution Vulnerability A stack-based buffer overflow vulnerability in Windows DHCP Client could allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-44815: DHCP Client Service Remote Code Execution Vulnerability This vulnerability has a CVSS:3.1 9.8 / 8.5 Policy Audit Control IDs (CIDs): 1264 Status of the ‘Dynamic Host Configuration Protocol (DHCP) Client’ service The following QQL will return a posture assessment for the CIDs for this Patch Tuesday: control.id: [1264]
ZDI: CVE-2026-44815 - DHCP Client Service Remote Code Execution Vulnerability. Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.
50.
Elevation of Privilege - Microsoft Exchange (CVE-2026-45504) - High [427]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00402, EPSS Percentile is 0.3175 |
51.
Elevation of Privilege - NT OS Kernel (CVE-2026-42980) - High [425]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | NT OS Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.8 | 10 | EPSS Probability is 0.02516, EPSS Percentile is 0.82751 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
52.
Elevation of Privilege - Winlogon (CVE-2026-42989) - High [425]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Winlogon | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.8 | 10 | EPSS Probability is 0.02536, EPSS Percentile is 0.8288 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
53.
Information Disclosure - Windows Shell (CVE-2026-42907) - High [424]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00657, EPSS Percentile is 0.46533 |
54.
Remote Code Execution - Windows Kerberos (CVE-2026-47288) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.22895 |
Qualys: CVE-2026-47288: Windows Kerberos Key Distribution Center (KDC) Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Kerberos may allow an authenticated attacker to execute code over an adjacent network.
55.
Elevation of Privilege - Windows Narrator Braille (CVE-2026-48565) - High [416]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.26214 |
56.
Denial of Service - ASP.NET Core (CVE-2026-45591) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | An open-source, server-side web-application framework designed for web development | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00766, EPSS Percentile is 0.50637 |
57.
Elevation of Privilege - Microsoft Graphics Component (CVE-2026-42986) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Graphics Component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.7 | 10 | EPSS Probability is 0.01628, EPSS Percentile is 0.73062 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
58.
Security Feature Bypass - Secure Boot (CVE-2026-45588) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15332 |
59.
Security Feature Bypass - Secure Boot (CVE-2026-45654) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.15853 |
ZDI: Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls.
60.
Security Feature Bypass - Secure Boot (CVE-2026-48568) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15331 |
61.
Security Feature Bypass - Secure Boot (CVE-2026-48575) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15332 |
62.
Security Feature Bypass - Windows Boot Manager (CVE-2026-47656) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15331 |
63.
Information Disclosure - Microsoft Exchange (CVE-2026-45503) - High [412]
Description: Server-side request forgery (ssrf) in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00428, EPSS Percentile is 0.3406 |
64.
Elevation of Privilege - Windows Kernel (CVE-2026-48583) - High [408]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11743 |
65.
Elevation of Privilege - Windows Device Health Attestation (DHA) (CVE-2026-33828) - High [404]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.1701 |
Qualys: CVE-2026-33828: Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.
66.
Elevation of Privilege - Windows Projected File System (CVE-2026-42828) - High [404]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.21343 |
67.
Elevation of Privilege - Windows Projected File System (CVE-2026-42837) - High [404]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.21342 |
68.
Elevation of Privilege - Windows Universal Disk Format File System Driver (UDFS) (CVE-2026-40404) - High [404]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.22578 |
69.
Remote Code Execution - Microsoft SharePoint Server (CVE-2026-47298) - High [404]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00496, EPSS Percentile is 0.3851 |
70.
Denial of Service - Windows Kerberos (CVE-2026-42903) - High [401]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00727, EPSS Percentile is 0.49268 |
71.
Security Feature Bypass - Secure Boot (CVE-2026-48578) - High [401]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Secure boot is a security standard developed by members of the PC industry to help make sure that a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM) | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00216, EPSS Percentile is 0.11839 |
72.
Security Feature Bypass - Windows BitLocker (CVE-2026-45658) - High [401]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14022 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
73.
Information Disclosure - Microsoft Teams for Android (CVE-2026-42835) - Medium [398]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Microsoft Teams for Android | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0.6 | 10 | EPSS Probability is 0.01095, EPSS Percentile is 0.61197 |
74.
Elevation of Privilege - Windows Kernel (CVE-2026-42984) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10551 |
75.
Elevation of Privilege - Windows Kernel (CVE-2026-45653) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10551 |
76.
Remote Code Execution - Microsoft Excel (CVE-2026-44817) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.20604 |
77.
Remote Code Execution - Microsoft Excel (CVE-2026-44820) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.20605 |
78.
Remote Code Execution - Microsoft Excel (CVE-2026-44823) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.21234 |
79.
Remote Code Execution - Microsoft Excel (CVE-2026-45469) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.20604 |
80.
Remote Code Execution - Microsoft Word (CVE-2026-45457) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.23813 |
81.
Remote Code Execution - Microsoft Word (CVE-2026-45471) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.21233 |
82.
Remote Code Execution - Microsoft Word (CVE-2026-45643) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.23813 |
83.
Remote Code Execution - Windows Hyper-V (CVE-2026-45607) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.21885 |
Qualys: CVE-2026-45607, CVE-2026-47652, & CVE-2026-45641: Windows Hyper-V Remote Code Execution Vulnerability An out-of-bounds read vulnerability in Windows Hyper-V could allow an unauthenticated attacker to execute code remotely.
84.
Remote Code Execution - Windows Hyper-V (CVE-2026-45641) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15271 |
Qualys: CVE-2026-45607, CVE-2026-47652, & CVE-2026-45641: Windows Hyper-V Remote Code Execution Vulnerability An out-of-bounds read vulnerability in Windows Hyper-V could allow an unauthenticated attacker to execute code remotely.
85.
Remote Code Execution - Windows Hyper-V (CVE-2026-47652) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.1629 |
Qualys: CVE-2026-45607, CVE-2026-47652, & CVE-2026-45641: Windows Hyper-V Remote Code Execution Vulnerability An out-of-bounds read vulnerability in Windows Hyper-V could allow an unauthenticated attacker to execute code remotely.
86.
Elevation of Privilege - Microsoft Cryptographic Services (CVE-2026-44810) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | he Cryptographic Services is a Microsoft Windows feature that encrypts and decrypts data on storage devices when they are accessed | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12091 |
Qualys: CVE-2026-44810: Microsoft Cryptographic Services Elevation of Privilege Vulnerability An improper authentication vulnerability in Windows Cryptographic Services could allow an unauthorized attacker to elevate privileges locally.
87.
Elevation of Privilege - Microsoft DWM Core Library (CVE-2026-45637) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13631 |
88.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45638) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13631 |
89.
Elevation of Privilege - Windows Bluetooth Service (CVE-2026-45605) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1363 |
90.
Elevation of Privilege - Windows Common Log File System Driver (CVE-2026-44809) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11741 |
91.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-42983) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1362 |
92.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-44802) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11742 |
93.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-44804) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11741 |
94.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-44807) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11742 |
95.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-44808) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11743 |
96.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-44811) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11742 |
97.
Elevation of Privilege - Windows DWM Core Library (CVE-2026-44813) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11742 |
98.
Elevation of Privilege - Windows Hotpatch Monitoring Service (CVE-2026-42910) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1363 |
99.
Elevation of Privilege - Windows Internet (wininet.dll) (CVE-2026-45592) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1363 |
100.
Elevation of Privilege - Windows Kernel-Mode Driver (CVE-2026-45600) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13631 |
101.
Elevation of Privilege - Windows Push Notifications (CVE-2026-42978) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08462 |
102.
Elevation of Privilege - Windows SDK (CVE-2026-45593) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13631 |
103.
Elevation of Privilege - Windows Universal Disk Format File System Driver (UDFS) (CVE-2026-40409) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.14804 |
104.
Remote Code Execution - Azure Kubernetes Service (AKS) (CVE-2026-32193) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Azure Kubernetes Service (AKS) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.21452 |
Qualys: CVE-2026-32193: Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability A path traversal vulnerability in Microsoft Azure Kubernetes Service may allow an authenticated attacker to execute code locally.
105.
Remote Code Execution - Microsoft Outlook and Word (CVE-2026-45456) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Outlook and Word | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.26493 |
Qualys: CVE-2026-45456, CVE-2026-47635, & CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability A type confusion vulnerability in Microsoft Office may allow an unauthenticated attacker to execute arbitrary code remotely.
106.
Remote Code Execution - Microsoft Outlook and Word (CVE-2026-45458) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Outlook and Word | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.26492 |
Qualys: CVE-2026-45456, CVE-2026-47635, & CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability A type confusion vulnerability in Microsoft Office may allow an unauthenticated attacker to execute arbitrary code remotely.
107.
Elevation of Privilege - Microsoft Dynamics 365 (on-premises) (CVE-2026-40371) - Medium [389]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Dynamics 365 (on-premises) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00517, EPSS Percentile is 0.39761 |
108.
Information Disclosure - Microsoft Office (CVE-2026-44821) - Medium [388]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00366, EPSS Percentile is 0.28265 |
109.
Information Disclosure - Windows DHCP Client (CVE-2026-45608) - Medium [388]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.16682 |
110.
Information Disclosure - Windows DWM Core Library (CVE-2026-48566) - Medium [388]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00356, EPSS Percentile is 0.27271 |
111.
Information Disclosure - Windows Push Notification (CVE-2026-42969) - Medium [388]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00356, EPSS Percentile is 0.2727 |
112.
Information Disclosure - Windows Push Notification (CVE-2026-42971) - Medium [388]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.33517 |
113.
Information Disclosure - Windows Telephony Server (CVE-2026-42968) - Medium [388]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00356, EPSS Percentile is 0.27271 |
114.
Elevation of Privilege - Program Compatibility Assistant Service (CVE-2026-45487) - Medium [380]
Description: Time-of-check time-of-use (TOCTOU) race condition in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | The Program Compatibility Assistant (PCA) Service (PcaSvc) is a built-in Windows background feature designed to help older software and legacy games run smoothly on modern versions of the operating system. It tracks app executions and automatically applies compatibility settings when it detects known issues. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04351 |
115.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-34335) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.0893 |
116.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-42911) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.0893 |
117.
Elevation of Privilege - Windows Bluetooth Port Driver (CVE-2026-45640) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.0893 |
118.
Elevation of Privilege - Windows DNS Client (CVE-2026-41108) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14429 |
119.
Elevation of Privilege - Windows Function Discovery Service (fdwsd.dll) (CVE-2026-42836) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07849 |
120.
Elevation of Privilege - Windows Push Notifications (CVE-2026-42977) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04664 |
121.
Elevation of Privilege - Windows Push Notifications (CVE-2026-42979) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04665 |
122.
Elevation of Privilege - Windows Push Notifications (CVE-2026-42991) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03774 |
123.
Elevation of Privilege - Windows Storage (CVE-2026-47648) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07604 |
124.
Elevation of Privilege - Windows Telephony Service (CVE-2026-42912) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08583 |
125.
Remote Code Execution - Microsoft Outlook and Word (CVE-2026-47635) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Outlook and Word | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.17503 |
Qualys: CVE-2026-45456, CVE-2026-47635, & CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability A type confusion vulnerability in Microsoft Office may allow an unauthenticated attacker to execute arbitrary code remotely.
126.
Remote Code Execution - Visual Studio Code MSSQL Extension (CVE-2026-47292) - Medium [380]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Visual Studio Code MSSQL Extension | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.23473 |
127.
Information Disclosure - Microsoft Excel (CVE-2026-44822) - Medium [379]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.33151 |
128.
Denial of Service - Microsoft Windows VMSwitch (CVE-2026-42915) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00517, EPSS Percentile is 0.39752 |
129.
Denial of Service - Windows Kerberos (CVE-2026-42914) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00729, EPSS Percentile is 0.49328 |
130.
Security Feature Bypass - Windows BitLocker (CVE-2026-45655) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00332, EPSS Percentile is 0.24798 |
131.
Security Feature Bypass - Windows Mark of the Web (CVE-2026-45595) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Windows component | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.23638 |
132.
Information Disclosure - Microsoft Exchange (CVE-2026-45502) - Medium [376]
Description: Server-side request forgery (ssrf) in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00424, EPSS Percentile is 0.33719 |
133.
Information Disclosure - Microsoft Office (CVE-2026-45460) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00334, EPSS Percentile is 0.25073 |
Qualys: CVE-2026-45460: Microsoft Office Information Disclosure Vulnerability An out-of-bounds read vulnerability in Microsoft Office could allow an unauthenticated attacker to disclose information locally.
134.
Information Disclosure - Windows Application Identity (AppID) (CVE-2026-45594) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.24057 |
135.
Information Disclosure - Windows DHCP Client (CVE-2026-45634) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.18976 |
136.
Information Disclosure - Windows DWM Core Library (CVE-2026-44814) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.16668 |
137.
Information Disclosure - Windows Managed Installer (CVE-2026-45604) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.18976 |
138.
Information Disclosure - Windows Push Notification (CVE-2026-42970) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.24057 |
139.
Information Disclosure - Windows Push Notification (CVE-2026-42973) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.24056 |
140.
Information Disclosure - Windows Shell (CVE-2026-42906) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.24056 |
141.
Remote Code Execution - Microsoft Excel (CVE-2026-44818) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | MS Office product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13502 |
142.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45596) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04279 |
143.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45598) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04278 |
144.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45601) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04278 |
145.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-45603) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04279 |
146.
Elevation of Privilege - Windows UI Automation Manager (uiamanager.dll) (CVE-2026-45597) - Medium [368]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00153, EPSS Percentile is 0.04767 |
147.
Elevation of Privilege - Microsoft Live Share Canvas SDK (CVE-2026-45644) - Medium [366]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Live Share Canvas SDK | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.32568 |
148.
Security Feature Bypass - Microsoft Visual Studio Code CoPilot Chat (CVE-2026-45482) - Medium [363]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Microsoft Visual Studio Code CoPilot Chat | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.20999 |
149.
Security Feature Bypass - UEFI Secure Boot (CVE-2026-45656) - Medium [363]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | UEFI Secure Boot | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.15745 |
150.
Elevation of Privilege - Visual Studio Code (CVE-2026-47281) - Medium [356]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.3 | 14 | Integrated development environment | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.30076 |
151.
Information Disclosure - Windows Hyper-V (CVE-2026-42972) - Medium [355]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Hardware virtualization component of the client editions of Windows NT | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.33517 |
152.
Elevation of Privilege - Microsoft Azure Network Adapter (CVE-2026-45476) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Azure Network Adapter | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.19212 |
Qualys: CVE-2026-45476: Microsoft Azure Network Adapter Elevation of Privilege Vulnerability A use-after-free vulnerability in the Linux MANA Driver allows an authenticated attacker to elevate local privileges.
153.
Elevation of Privilege - Microsoft Kinect (CVE-2026-41092) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Kinect | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18103 |
154.
Elevation of Privilege - Microsoft PC Manager (CVE-2026-50511) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft PC Manager | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.19174 |
155.
Elevation of Privilege - Microsoft PowerToys (CVE-2026-42902) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft PowerToys | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18103 |
Rapid7: The Microsoft PowerToys utility provides a wide variety of useful control and configuration options for Windows power users which aren’t otherwise easily accessible. It turns out that PowerToys also offers an undocumented extra: local elevation of privilege to SYSTEM via successful exploitation of CVE-2026-42902. It is worth noting that the fix was included in PowerToys v0.99.1 on April 29, 2026, without any apparent mention in the release notes. Attackers with patch-diffing toolkits may well take note of this discrepancy.
156.
Elevation of Privilege - NT OS Kernel (CVE-2026-42916) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | NT OS Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.21342 |
157.
Denial of Service - Windows Network Controller (NC) Host Agent (CVE-2026-44805) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.24282 |
158.
Information Disclosure - Microsoft Office (CVE-2026-45485) - Medium [352]
Description: Out-of-bounds read in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Microsoft Office is a suite of applications designed to help with productivity and completing common tasks on a computer | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.2609 |
159.
Spoofing - Windows NTLM (CVE-2026-50508) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.9 | 14 | A suite of security protocols to authenticate users' identity and protect the integrity and confidentiality of their activity | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.0049, EPSS Percentile is 0.38189 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
160.
Security Feature Bypass - Microsoft PC Manager (CVE-2026-49161) - Medium [351]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Microsoft PC Manager | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00192, EPSS Percentile is 0.08995 |
161.
Elevation of Privilege - Visual Studio Code (CVE-2026-40376) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.3 | 14 | Integrated development environment | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.006, EPSS Percentile is 0.4399 |
162.
Elevation of Privilege - .NET SDK (CVE-2026-45490) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | .NET SDK | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12171 |
163.
Elevation of Privilege - Microsoft PC Manager (CVE-2026-50512) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft PC Manager | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.10783 |
164.
Security Feature Bypass - UEFI Secure Boot (CVE-2026-8863) - Medium [339]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | UEFI Secure Boot | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.0 | 10 | EPSS Probability is 0.00078, EPSS Percentile is 0.00193 |
Tenable: Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.
165.
Elevation of Privilege - Microsoft Office Click-To-Run (CVE-2026-47293) - Medium [330]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Office Click-To-Run | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09429 |
166.
Information Disclosure - Visual Studio Code (CVE-2026-47284) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.3 | 14 | Integrated development environment | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00598, EPSS Percentile is 0.43915 |
167.
Spoofing - Microsoft Exchange (CVE-2026-47631) - Medium [323]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15314 |
168.
Security Feature Bypass - Microsoft Excel (CVE-2026-45459) - Medium [320]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | MS Office product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.23787 |
169.
Elevation of Privilege - Microsoft Defender for Endpoint for Mac (CVE-2026-45647) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Microsoft Defender for Endpoint for Mac | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.1 | 10 | EPSS Probability is 0.00197, EPSS Percentile is 0.09527 |
170.
Security Feature Bypass - Visual Studio Code (CVE-2026-48569) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | Integrated development environment | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.20185 |
171.
Tampering - Windows Dynamic Host Configuration Protocol (DHCP) (CVE-2026-45602) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.17318 |
172.
Denial of Service - Microsoft UxTheme Library (uxtheme.dll) (CVE-2026-45606) - Medium [315]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Microsoft UxTheme Library (uxtheme.dll) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.26797 |
173.
Memory Corruption - ARM processor (CVE-2025-10263) - Medium [315]
Description: Arm C1-Ultra, C1-Premium,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Processor | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.30637 |
Qualys: CVE-2025-10263: ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] An attacker could exploit the vulnerability by triggering a specific timing condition during a memory permission change, causing a memory write to be applied using outdated permissions. Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.
Tenable: Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.
174.
Spoofing - Microsoft Exchange (CVE-2026-45500) - Medium [311]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00382, EPSS Percentile is 0.29886 |
175.
Spoofing - Microsoft Exchange (CVE-2026-45501) - Medium [311]
Description: Improper neutralization of input during web page generation ('cross-site scripting') in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Microsoft Exchange Server is a mail server and calendaring server developed by Microsoft | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.21125 |
176.
Spoofing - Azure Stack Edge (CVE-2026-41098) - Medium [309]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Azure Stack Edge | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00744, EPSS Percentile is 0.49856 |
177.
Information Disclosure - Microsoft Excel (CVE-2026-45455) - Medium [307]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | MS Office product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.2121 |
178.
Information Disclosure - Microsoft Word (CVE-2026-45466) - Medium [307]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.2453 |
179.
Spoofing - Microsoft SharePoint Server (CVE-2026-45481) - Medium [285]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00482, EPSS Percentile is 0.3769 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
180.
Spoofing - Microsoft SharePoint Server (CVE-2026-47634) - Medium [273]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00392, EPSS Percentile is 0.30843 |
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
181.
Spoofing - Microsoft SharePoint Server (CVE-2026-48560) - Medium [273]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00735, EPSS Percentile is 0.49565 |
182.
Spoofing - Office for Android (CVE-2026-45649) - Medium [273]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Office for Android | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00336, EPSS Percentile is 0.25214 |
183.
Tampering - .NET (CVE-2026-45491) - Medium [265]
Description: Improper link resolution before file access ('link following') in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.7 | 14 | .NET | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.21555 |
184.
Spoofing - Microsoft SharePoint Server (CVE-2026-33113) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00409, EPSS Percentile is 0.32445 |
185.
Spoofing - Microsoft SharePoint Server (CVE-2026-45453) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.004, EPSS Percentile is 0.31613 |
186.
Spoofing - Microsoft SharePoint Server (CVE-2026-45462) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31212 |
187.
Spoofing - Microsoft SharePoint Server (CVE-2026-45464) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.004, EPSS Percentile is 0.31613 |
188.
Spoofing - Microsoft SharePoint Server (CVE-2026-45465) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.004, EPSS Percentile is 0.31614 |
189.
Spoofing - Microsoft SharePoint Server (CVE-2026-45467) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31212 |
190.
Spoofing - Microsoft SharePoint Server (CVE-2026-45468) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31212 |
191.
Spoofing - Microsoft SharePoint Server (CVE-2026-45479) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31214 |
192.
Spoofing - Microsoft SharePoint Server (CVE-2026-47636) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.004, EPSS Percentile is 0.31614 |
193.
Spoofing - Microsoft SharePoint Server (CVE-2026-47637) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31213 |
194.
Spoofing - Microsoft SharePoint Server (CVE-2026-47638) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31213 |
195.
Spoofing - Microsoft SharePoint Server (CVE-2026-47639) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.004, EPSS Percentile is 0.31614 |
196.
Spoofing - Microsoft SharePoint Server (CVE-2026-47640) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31213 |
197.
Spoofing - Microsoft SharePoint Server (CVE-2026-47641) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31214 |
198.
Spoofing - Microsoft SharePoint Server (CVE-2026-48562) - Medium [250]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft SharePoint Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.31214 |
199.
Spoofing - Microsoft Office Project Server (CVE-2026-45483) - Medium [238]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft Office Project Server | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.18743 |
200.
Tampering - Visual Studio Code (CVE-2026-47287) - Medium [234]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.3 | 15 | Tampering | |
| 0.3 | 14 | Integrated development environment | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.3927 |
201.
Spoofing - Microsoft Azure Attestation service and Device Health Attestation Service (CVE-2026-45642) - Medium [226]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Microsoft Azure Attestation service and Device Health Attestation Service | |
| 0.4 | 10 | CVSS Base Score is 3.9. According to Microsoft data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.16833 |
202.
Spoofing - Microsoft Bing Search (CVE-2026-45650) - Medium [200]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.2 | 14 | Microsoft Bing Search | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Microsoft data source | |
| 0.4 | 10 | EPSS Probability is 0.00486, EPSS Percentile is 0.37911 |
Qualys: CVE-2026-47291: HTTP.sys Remote Code Execution Vulnerability An integer overflow vulnerability in Windows HTTP.sys may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-47291: HTTP.sys Remote Code Execution Vulnerability This vulnerability has a CVSS:3.1 9.8 / 8.5 Policy Audit Control IDs (CIDs): 32308 Status of the ‘MaxRequestBytes (Windows HTTP.sys registry)’ Setting The following QQL will return a posture assessment for the CIDs for this Patch Tuesday: control.id: [32308] The next Patch Tuesday is scheduled for July 14, and we will provide details and patch analysis then. Until next Patch Tuesday, stay safe and secure. Be sure to subscribe to the ‘This Month in Vulnerabilities and Patches’ webinar.’
ZDI: CVE-2026-47291 - HTTP.sys Remote Code Execution Vulnerability. Our second CVSS 9.8 bug of the month, this also allows remote, unauthenticated attackers to execute code on affected systems without user interaction. However, there is a caveat. Systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this bug. You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as “Exploitation more likely”, so I would definitely check your registry settings.
Qualys: CVE-2026-49160: HTTP.sys Denial of Service Vulnerability Uncontrolled resource consumption in HTTP/2 could allow an unauthenticated attacker to deny service over a network.
Tenable: Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
Tenable: CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability
Tenable: CVE-2026-49160 is a denial of service (DoS) vulnerability affecting HTTP.sys. It received a CVSSv3 score of 7.5 and is rated as important. It was assessed as “Exploitation More Likely” and publicly disclosed prior to a patch being available. According to the advisory, this DoS affects HTTP/2. The advisory notes that this update adds a MaxHeadersCount registry setting which can be used to limit the number of headers included in HTTP/2 and HTTP/3 requests.
Rapid7: Every so often, a new round of denial of service vulnerabilities emerge which affect web servers implementing HTTP/2 and HTTP/3 standards. This class of vulnerabilities is likely to expand further as researchers, including the discoverers of CVE-2026-49160, use advances in LLM capability to probe not just specific software, but also the standards on which software rests. Microsoft warns that exploitation leads to uncontrolled resource consumption over a network, and expects that exploitation is more likely. The advisory credits both a third-party research firm and OpenAI’s Codex.
Qualys: CVE-2026-45657: Windows Kernel Remote Code Execution Vulnerability A use-after-free vulnerability in the Windows Kernel could allow an unauthenticated attacker to execute code remotely.
Qualys: CVE-2026-42987: Windows Deployment Services (WDS) Remote Code Execution Vulnerability A use-after-free in Windows Deployment Services could allow an unauthenticated attacker to execute code over a network.
ZDI: CVE-2026-45657 - Windows Kernel Remote Code Execution Vulnerability. This CVSS 9.8 bug allows remote, unauthenticated attackers to execute code at SYSTEM level without user interaction. Yup – this is wormable. The problem lies in the way the kernel handles TCP/IP. This was listed as “Exploitation Less Likely” by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly.
Qualys: CVE-2026-45648: Windows Active Directory Domain Services Remote Code Execution Vulnerability A stack-based buffer overflow vulnerability in Active Directory Domain Services may allow an authenticated attacker to execute code remotely.
Qualys: CVE-2026-47289, CVE-2026-47654, CVE-2026-42992, CVE-2026-44799, CVE-2026-44801, CVE-2026-42985, & CVE-2026-48563: Remote Desktop Client Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Remote Desktop Client may allow an unauthenticated attacker to execute code over a network.
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 | Remote Desktop Client Remote Code Execution Vulnerability
Tenable: CVE-2026-42909, CVE-2026-42913, CVE-2026-42985, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799, CVE-2026-44801, CVE-2026-47289, CVE-2026-47653, CVE-2026-47654 and CVE-2026-48563 are RCE vulnerabilities affecting Remote Desktop Client. CVSSv3 scores ranged from 8.8 (CVE-2026-42985, CVE-2026-47289 and CVE-2026-47653) to 7.5 and seven were rated as critical while CVE-2026-42993, CVE-2026-42909, CVE-2026-47653 and CVE-2026-42913 were rated as important. Successful exploitation would require a victim to connect to an attacker controlled server using an affected version of the Remote Desktop Client. This action could trigger a heap-based buffer overflow, resulting in remote code execution.
Tenable: While no public details have been released about these vulnerabilities as of June 9, Microsoft has assessed CVE-2026-42985 as “Exploitation More Likely” while the other CVEs were classified as either “Exploitation Unlikely” or “Exploitation Less Likely.” Patches are available for supported versions of Windows and Windows Server.
Qualys: CVE-2026-26142: Nuance PowerScribe Remote Code Execution Vulnerability Deserialization of untrusted data in Nuance PowerScribe may allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-45461, CVE-2026-45463, CVE-2026-45472, & CVE-2026-45474: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Microsoft Office could allow an unauthenticated attacker to execute code remotely.
Qualys: CVE-2026-44803 & CVE-2026-44812: Windows Graphics Component Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Win32K – GRFX could allow an unauthenticated attacker to execute code locally.
Qualys: CVE-2026-48574: Windows Media Remote Code Execution Vulnerability A heap-based buffer overflow vulnerability in Windows Media may allow an unauthenticated attacker to execute code locally.
Qualys: CVE-2026-44815: DHCP Client Service Remote Code Execution Vulnerability A stack-based buffer overflow vulnerability in Windows DHCP Client could allow an unauthenticated attacker to execute code over a network.
Qualys: CVE-2026-44815: DHCP Client Service Remote Code Execution Vulnerability This vulnerability has a CVSS:3.1 9.8 / 8.5 Policy Audit Control IDs (CIDs): 1264 Status of the ‘Dynamic Host Configuration Protocol (DHCP) Client’ service The following QQL will return a posture assessment for the CIDs for this Patch Tuesday: control.id: [1264]
ZDI: CVE-2026-44815 - DHCP Client Service Remote Code Execution Vulnerability. Here’s another CVSS 9.8 that has an odd incongruity. Although the CVSS says no permissions are required for exploitation, the write-up states it must be an “authenticated” user. I would err on the side of caution here and believe the CVSS. If that’s correct, then we have another bug where a remote, unauthenticated attacker could execute code on affected systems without user interaction. And since the DHCP client is on every OS, it’s a juicy target. This is another one to test and deploy with haste.
Qualys: CVE-2026-47288: Windows Kerberos Key Distribution Center (KDC) Remote Code Execution Vulnerability An integer overflow vulnerability in Windows Kerberos may allow an authenticated attacker to execute code over an adjacent network.
Qualys: CVE-2026-45607, CVE-2026-47652, & CVE-2026-45641: Windows Hyper-V Remote Code Execution Vulnerability An out-of-bounds read vulnerability in Windows Hyper-V could allow an unauthenticated attacker to execute code remotely.
Qualys: CVE-2026-32193: Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability A path traversal vulnerability in Microsoft Azure Kubernetes Service may allow an authenticated attacker to execute code locally.
Qualys: CVE-2026-45456, CVE-2026-47635, & CVE-2026-45458: Microsoft Outlook and Word Remote Code Execution Vulnerability A type confusion vulnerability in Microsoft Office may allow an unauthenticated attacker to execute arbitrary code remotely.
ZDI: Moving on to the more than 20 security feature bypass (SFB) bugs in the June release, there are a total of 10 that impact Secure Boot. All carry scope change (S:C) in the CVSS, meaning successful exploitation affects security boundaries beyond the vulnerable component itself — specifically the ability to load untrusted code at boot, bypass Virtual Secure Mode, and undermine boot integrity guarantees. CVE-2026-45654 explicitly calls out VSM exposure. The bulk of these are credited to Alon Leviev (STORM), which is notable given his prior BootKitty/BlackLotus-adjacent research. The bugs in the Windows Boot Manager have a similar impact as the Secure Boot bugs. The UEFI Secure Boot vulnerabilities go a layer deeper. They require either local admin or physical access but could allow for the running of untrusted code even before the OS loads. Rootkits anyone? The four bugs in BitLocker all require physical access but could yield encrypted data if exploited. The bug in Windows Administration Protection allows attackers to bypass the feature that prevents standard-user apps from performing admin-level actions. The bug in Visual Studio Copilot Chat could be the most interesting non-boot bug here as it allows authentication impersonation. Mark of the Web (MotW) and Excel vulns could bypass user warnings. Lastly, the bug in PC Manager bypasses expected user controls.
Qualys: CVE-2026-50507: Windows BitLocker Security Feature Bypass Vulnerability A protection mechanism failure in Windows BitLocker may allow an unauthenticated attacker to bypass a security feature with a physical attack.
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
Tenable: Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)
Tenable: CVE-2026-50507 | Windows BitLocker Security Feature Bypass Vulnerability
Tenable: CVE-2026-50507 is a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.8 and is rated as important. It was publicly disclosed prior to a patch being available and assessed as “Exploitation More Likely” according to Microsoft's Exploitability Index.
Tenable: According to reports, CVE-2026-41091 is RedSun, a zero-day vulnerability disclosed by a researcher named Chaotic Eclipse or Nightmare Eclipse on April 15, 2026. This researcher has also published several additional zero-days recently, including BlueHammer (CVE-2026-33825), GreenPlasma, MiniPlasma and collaborated on Bitskrieg (CVE-2026-50507). It has since been exploited in the wild and added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (CISA KEV) catalog on May 20.
ZDI: CVE-2026-45585/CVE-2026-50507 - Windows BitLocker Security Feature Bypass Vulnerability. If you’ve followed the ongoing saga of Nightmare Eclipse vs. MSRC, the bugs should look familiar. One is definitely a fix for “YellowKey”, while the other appears to be a fix for “GreenPlasma”. The researcher has promised a “bone shattering” drop on June 14, so let’s hope Microsoft is able to reach some understanding with the researcher before more 0-days are released. Also, there is a script provided by Microsoft as a mitigation, but the better strategy is to test and deploy the updates.
Tenable: Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.
Qualys: CVE-2026-45586: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability A link-following vulnerability in the Windows Collaborative Translation Framework could allow an authenticated attacker to elevate privileges locally. Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.
Tenable: CVE-2026-45586 | Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Tenable: CVE-2026-45586 is an EoP vulnerability affecting Windows Collaborative Translation Framework (CTFMON), a process that supports voice and handwriting recognition. It was assigned a CVSSv3 score of 7.8 and rated as important. This EoP flaw was one of three zero-days disclosed prior to patches being made available. Successful exploitation would grant an attacker SYSTEM privileges and Microsoft has assessed this vulnerability as “Exploitation More Likely.”
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
Qualys: CVE-2026-33828: Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.
Qualys: CVE-2026-44810: Microsoft Cryptographic Services Elevation of Privilege Vulnerability An improper authentication vulnerability in Windows Cryptographic Services could allow an unauthorized attacker to elevate privileges locally.
Qualys: CVE-2026-45476: Microsoft Azure Network Adapter Elevation of Privilege Vulnerability A use-after-free vulnerability in the Linux MANA Driver allows an authenticated attacker to elevate local privileges.
Rapid7: The Microsoft PowerToys utility provides a wide variety of useful control and configuration options for Windows power users which aren’t otherwise easily accessible. It turns out that PowerToys also offers an undocumented extra: local elevation of privilege to SYSTEM via successful exploitation of CVE-2026-42902. It is worth noting that the fix was included in PowerToys v0.99.1 on April 29, 2026, without any apparent mention in the release notes. Attackers with patch-diffing toolkits may well take note of this discrepancy.
Qualys: CVE-2026-45460: Microsoft Office Information Disclosure Vulnerability An out-of-bounds read vulnerability in Microsoft Office could allow an unauthenticated attacker to disclose information locally.
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
Qualys: Other Microsoft Vulnerability Highlights CVE-2026-45658 is a security feature bypass vulnerability in Windows BitLocker. An attacker may exploit the vulnerability to gain access to encrypted data. CVE-2026-47634 and CVE-2026-45481 are spoofing vulnerabilities in Microsoft SharePoint Server. The cross-site scripting vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-42905 is an elevation of privilege vulnerability in Windows DWM Core Library. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42980 is an elevation of privilege vulnerability in the NT OS Kernel. An integer underflow vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42986 is an elevation of privilege vulnerability in the Microsoft Graphics Component. The use-after-free vulnerability may allow an authenticated attacker to gain SYSTEM privileges. CVE-2026-42989 is an elevation of privilege vulnerability in the Winlogon. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. CVE-2026-50508 is a spoofing vulnerability in the Windows NTLM. Successful exploitation of the vulnerability may allow an unauthenticated attacker to perform network spoofing.
Qualys: CVE-2025-10263: ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel] An attacker could exploit the vulnerability by triggering a specific timing condition during a memory permission change, causing a memory write to be applied using outdated permissions. Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges.
Tenable: Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release.