
























Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday, including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Microsoft has now taken the pursuit of minimalism much further, since today’s Security Update Guide no longer lists out even Microsoft vulnerabilities! Instead, we now receive a summary table of vulnerability counts by product family, as well as a new slimline “Notable CVEs” section. All of this only serves to illustrate the recent industry-wide trend of exploding vulnerability report counts, with an associated uptick in the publication of remediations as a trailing indicator.
Today sees the publication of CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer, and published today in coordination with Microsoft, this vulnerability is the first in a pair of exploits which, when chained together, can lead to unauthenticated remote code execution against a vulnerable SharePoint server. Patches are available for SharePoint Server Subscription Edition, 2019, and 2016. As the full Rapid7 blog post sets out, the second vulnerability in the full RCE chain remains embargoed for now, with Microsoft expected to publish patches for that second vulnerability as part of Patch Tuesday August 2026. Microsoft noted: “We would like to thank Rapid7 for responsibly reporting this issue through coordinated vulnerability disclosure.”
It’s a rare Patch Tuesday which doesn’t include multiple SharePoint fixes, and today is no exception. Microsoft is aware of existing in-the-wild exploitation of CVE-2026-56164, where successful exploitation allows an attacker to elevate privileges over a network, with no existing privileges required, and low attack complexity since “an attacker does not require significant prior knowledge of the system, and can achieve repeatable success”. This is as good an example as any that a relatively low CVSS v3 base score (5.3) may be an imperfect signal concealing something much spicier, and Microsoft acknowledges that possibility by assigning a severity rating of Important. Microsoft certainly intended to list CVE-2026-56164 in the new Notable CVEs section of the Security Update Guide instead of erroneously listing CVE-2026-56155 twice, and it’s likely that this will be corrected shortly.
After years of relative stability, the Patch Tuesday process has experienced significant turbulence so far in 2026. As well as the AI-fuelled exponential growth of vulnerability reporting and discovery, Microsoft is grappling with the emergence of a series of vulnerabilities disclosed in such a way as to bring maximum discomfort for Redmond. Pseudonymous researcher Nightmare Eclipse dropped another Defender elevation of privilege vulnerability in the hours following Patch Tuesday June 2026, which Microsoft subsequently published and patched as CVE-2026-50656, along with a terse acknowledgement of the vulnerability’s celebrity nickname of RoguePlanet. Recently, Nightmare Eclipse has given conflicting estimates of what sort of surprises Microsoft can expect today, as well as claiming that the CVE-2026-50656 patches introduce a new avenue for a disk exhaustion attack. Today, a new proof of concept for a further vulnerability nicknamed LegacyHive has emerged from the same source, which appears to allow a non-privileged user to mount another user’s user hive.
Microsoft BitLocker receives patches today for a publicly-known security feature bypass vulnerability. The advisory for CVE-2026-50661 explains that an unauthorized attacker with physical access to the target machine can bypass Windows BitLocker. While Microsoft doesn’t confirm either way, it’s very probable that this is a patch for the GreatXML vulnerability which Nightmare Eclipse announced the day after Patch Tuesday June 2026.
Active Directory administrators should note the emergence today of CVE-2026-56155, an exploited-in-the-wild elevation of privilege vulnerability in Active Directory Federation Services which allows an authorized attacker to elevate privileges locally. Eight other vulnerabilities are also published today in Active Directory Federation Services, all ranked as Important on Microsoft’s proprietary severity ranking scale. The advisory doesn’t explicitly describe the location of the attacker, but it’s likely that an attacker would need an existing toehold on the target system to chain together with the elevation of privilege opportunity on offer here.
Historically, Patch Tuesday hasn’t seen too many security patches for video games. However, Age of Empires II: Definitive Edition is a new entrant to the Microsoft CVE roster today. Veteran AoE2 players may well be familiar with dangerous opposition early game strategies such as the Persian Town Center nuisance or the Aztec monk rush, but anyone who opens a malicious game scenario file without applying the patch for CVE-2026-50663 might suffer a serious defeat. Successful exploitation allows an attacker to place malicious files in unexpected locations, potentially enabling code execution on the target system.
As Rapid7 noted last month, there are some significant Microsoft product lifecycle changes taking place in mid-July. SQL Server 2016 moves beyond regular extended support and into the pay-to-play Extended Security Updates (ESU) phase from July 15, 2026, and its older sibling SQL Server 2014 moves into the third and final year of ESU. Also on July 14, 2026, SharePoint Server 2016 and 2019 reach extended end date, and since there’s no ESU available, the only remaining option for fully-supported self-hosted SharePoint after today is SharePoint Subscription Edition. The July 2026 lifecycle casualties continue with Project Server 2016 and 2019, Dynamics GP 2016 and 2016 R2, InfoPath 2013, and SharePoint Designer 2013, which also all reach their Extended End Dates, ending their supported lifecycles. Visual Studio 2022 Version 17.12 Long-Term Servicing Channel (LTSC) reaches its release end date on July 14, leaving either the Visual Studio 2022 current channel or an upgrade to Visual Studio 2026 as supported options.
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-58617 | M365 Copilot for iOS Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-58595 | Microsoft Bing App for IOS Spoofing Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-48561 | Microsoft Copilot Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.6 |
| CVE-2026-58636 | Microsoft PC Manager Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-50438 | Microsoft PC Manager Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-54124 | Windows Terminal Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-50652 | Azure Active Directory Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50653 | Azure Active Directory Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-57969 | Azure CycleCloud Elevation of Privilege Vulnerability | N/A | No | 8.8 |
| CVE-2026-58279 | Azure CycleCloud Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-47632 | Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-50338 | Azure Spring Apps Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.2 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-47302 | .NET Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50525 | .NET Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50651 | .NET Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-57108 | .NET Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50524 | .NET Framework Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50527 | .NET Framework Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50648 | .NET Framework Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50650 | .NET Framework Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-50646 | .NET Framework Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-50649 | .NET Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-47304 | .NET Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.1 |
| CVE-2026-50528 | .NET Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.2 |
| CVE-2026-50659 | .NET Spoofing Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-50526 | .NET Tampering Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-56170 | ASP.NET Core Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-47300 | ASP.NET Core Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-47303 | ASP.NET Core Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-47282 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-41109 | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-50506 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-45646 | OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability | Exploitation Less Likely | No | 7.5 |
| CVE-2026-50520 | Visual Studio Code Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.4 |
| CVE-2026-45496 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-57101 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-57102 | Visual Studio Code Security Feature Bypass Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-47305 | Visual Studio Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-48581 | Surface Broker SDMA Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-55944 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-50678 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.6 |
| CVE-2026-54988 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 6.1 |
| CVE-2026-48580 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-50408 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55046 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55138 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55054 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-55122 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-55898 | Microsoft Excel Information Disclosure Vulnerability | Exploitation Unlikely | No | 6.1 |
| CVE-2026-50675 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55899 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55948 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-58618 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-47642 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55024 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55025 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-55031 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55048 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55029 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55039 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55041 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55136 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-55141 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55036 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55044 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55037 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55058 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55137 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55053 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55131 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-54131 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55947 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55949 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-56156 | Microsoft Excel Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-56193 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.1 |
| CVE-2026-55023 | Microsoft Office Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-55026 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.2 |
| CVE-2026-55027 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55028 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55047 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55035 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55057 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55042 | Microsoft Office Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-55139 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-50665 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-56192 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-56195 | Microsoft Office Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55121 | Microsoft Office Information Disclosure Vulnerability | Exploitation Unlikely | No | 5.5 |
| CVE-2026-47290 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-50301 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-50314 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-50467 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55017 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55018 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55022 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55125 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55045 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.4 |
| CVE-2026-55049 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55129 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55056 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55140 | Microsoft Office Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55133 | Microsoft OneNote Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55043 | Microsoft PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55123 | Microsoft PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55120 | Microsoft PowerPoint Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55052 | Microsoft SharePoint Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-58277 | Microsoft SharePoint Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Exploitation Detected | No | 5.3 |
| CVE-2026-55051 | Microsoft SharePoint Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | Exploitation More Likely | No | 9.1 |
| CVE-2026-54108 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-55016 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Less Likely | No | 4.6 |
| CVE-2026-55019 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Unlikely | No | 4.6 |
| CVE-2026-55020 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Unlikely | No | 4.6 |
| CVE-2026-55021 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Unlikely | No | 7.3 |
| CVE-2026-55030 | Microsoft SharePoint Server Spoofing Vulnerability | N/A | No | 4.6 |
| CVE-2026-55034 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-55126 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Less Likely | No | 7.3 |
| CVE-2026-55135 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Less Likely | No | 4.6 |
| CVE-2026-56157 | Microsoft SharePoint Server Spoofing Vulnerability | Exploitation Less Likely | No | 5.4 |
| CVE-2026-55050 | Microsoft Word Information Disclosure Vulnerability | N/A | No | 5.5 |
| CVE-2026-55124 | Microsoft Word Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55142 | Microsoft Word Information Disclosure Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-55032 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55033 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55127 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55055 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55038 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-55132 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55134 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-55128 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-55130 | Microsoft Word Remote Code Execution Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-50387 | Windows GDI Elevation of Privilege Vulnerability | Exploitation More Likely | No | 7.8 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-40553 | Stack-based buffer overflow in gawk | n/a | No | |
| CVE-2026-40469 | Heap buffer overflow in gawk | n/a | No | |
| CVE-2026-40468 | Heap buffer overflow in gawk | n/a | No | |
| CVE-2026-40467 | Use after free in gawk | n/a | No | |
| CVE-2026-57968 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-57973 | Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability | Exploitation Less Likely | No | 6.3 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-50663 | Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-50510 | GitHub Copilot Remote Code Execution Vulnerability | N/A | No | 7.8 |
| CVE-2026-55010 | Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-55145 | Outlook Copilot Tampering Vulnerability | N/A | No | 6.3 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-55006 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55009 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 7.8 |
| CVE-2026-55005 | Microsoft Exchange Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-55008 | Microsoft Exchange Server Spoofing Vulnerability | Exploitation More Likely | No | 9.6 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-56642 | Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability | Exploitation Unlikely | No | 8.8 |
| CVE-2026-58647 | Microsoft PowerBI Report Server Spoofing Vulnerability | Exploitation Unlikely | No | 8.0 |
| CVE-2026-47296 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55002 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-47295 | Microsoft SQL Server Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-50468 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-54116 | Microsoft SQL Server Information Disclosure Vulnerability | Exploitation Less Likely | No | 6.5 |
| CVE-2026-54117 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
| CVE-2026-54118 | Microsoft SQL Server Remote Code Execution Vulnerability | Exploitation Less Likely | No | 8.8 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-50658 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 7.0 |
| CVE-2026-56178 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 5.5 |
| CVE-2026-50657 | Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability | Exploitation Less Likely | No | 4.7 |
| CVE-2026-55011 | Microsoft Defender Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
| CVE-2026-55012 | Microsoft Defender Remote Code Execution Vulnerability | Exploitation Less Likely | No | 7.8 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability | Exploitation Detected | No | 7.8 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Exploitation Detected | No | 5.3 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-50661 | Windows BitLocker Security Feature Bypass Vulnerability | Exploitation Less Likely | Yes | 6.1 |
CVE | Title | Exploitation status | Publicly disclosed? | CVSS v3 base score |
|---|---|---|---|---|
| CVE-2026-56159 | DHCP Server Service Remote Code Execution Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-48561 | Microsoft Copilot Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.6 |
| CVE-2026-55944 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-55008 | Microsoft Exchange Server Spoofing Vulnerability | Exploitation More Likely | No | 9.6 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | Exploitation More Likely | No | 9.1 |
| CVE-2026-57092 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | Exploitation Less Likely | No | 9.9 |
| CVE-2026-55010 | Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-54990 | Remote Desktop Client Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-56190 | Remote Desktop Protocol Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-42990 | SQL Server ODBC driver Elevation of Privilege Vulnerability | Exploitation Unlikely | No | 9.8 |
| CVE-2026-50518 | Windows DHCP Server Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
| CVE-2026-49172 | Windows FTP Service Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-50380 | Windows GDI+ Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.6 |
| CVE-2026-49798 | Windows Kernel Elevation of Privilege Vulnerability | Exploitation More Likely | No | 9.3 |
| CVE-2026-50447 | Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability | Exploitation Less Likely | No | 9.8 |
| CVE-2026-56188 | Windows Server Network driver Remote Code Execution Vulnerability | Exploitation More Likely | No | 9.8 |
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。