| | CVE-2026-33110 | Microsoft | high | 8.8 | 0.5%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33112 | Microsoft | high | 8.8 | 0.5%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-33117 | Microsoft | critical | 9.1 | 0.0%
| | Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature ov… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-33821 | Microsoft | high | 7.7 | 0.1%
| | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attac… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-33833 | Microsoft | high | 8.2 | 0.5%
| | Improper neutralization of special elements in output used by a downstream component ('injection') i… | May 12, 2026 | Jun 18, 2026 |
| | CVE-2026-35429 | Microsoft | medium | 4.3 | 0.1%
| | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all… | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-35433 | Microsoft | high | 7.3 | 0.7%
| | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | May 12, 2026 | Jul 15, 2026 |
| | CVE-2026-35436 | Microsoft | high | 8.8 | 0.0%
| | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-35438 | Microsoft | high | 8.3 | 0.1%
| | Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges ov… | May 12, 2026 | May 28, 2026 |
| | CVE-2026-35439 | Microsoft | high | 8.8 | 0.5%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-35440 | Microsoft | medium | 5.5 | 0.0%
| | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized … | May 12, 2026 | May 19, 2026 |
| | CVE-2026-40357 | Microsoft | high | 8.8 | 0.5%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40358 | Microsoft | high | 8.4 | 0.1%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-40359 | Microsoft | high | 7.8 | 0.1%
| | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 12, 2026 | May 19, 2026 |
| | CVE-2026-40360 | Microsoft | high | 7.8 | 0.1%
| | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information… | May 12, 2026 | May 19, 2026 |
| | CVE-2026-40361 | Microsoft | high | 8.4 | 0.1%
| | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | May 12, 2026 | Jun 3, 2026 |
| | CVE-2026-40362 | Microsoft | high | 7.8 | 0.1%
| | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-40363 | Microsoft | high | 8.4 | 0.1%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | May 12, 2026 | May 19, 2026 |
| | CVE-2026-40364 | Microsoft | high | 8.4 | 0.2%
| | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una… | May 12, 2026 | May 19, 2026 |
| | CVE-2026-40365 | Microsoft | high | 8.8 | 0.1%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-40366 | Microsoft | high | 8.4 | 0.1%
| | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una… | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-40367 | Microsoft | high | 8.4 | 0.1%
| | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una… | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-40368 | Microsoft | high | 8.0 | 0.3%
| | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex… | May 12, 2026 | May 13, 2026 |
| | CVE-2026-40370 | Microsoft | high | 8.8 | 0.5%
| | External control of file name or path in SQL Server allows an authorized attacker to execute code ov… | May 12, 2026 | Jun 18, 2026 |
| | CVE-2026-40374 | Microsoft | medium | 6.5 | 0.1%
| | Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized at… | May 12, 2026 | May 19, 2026 |
| | CVE-2026-40379 | Microsoft | critical | 9.3 | 0.1%
| | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized … | May 12, 2026 | May 21, 2026 |
| | CVE-2026-40381 | Microsoft | high | 7.8 | 0.0%
| | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate pr… | May 12, 2026 | May 18, 2026 |
| | CVE-2026-40416 | Microsoft | medium | 4.3 | 0.0%
| | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all… | May 12, 2026 | May 18, 2026 |
| | CVE-2026-40417 | Microsoft | high | 7.8 | 0.3%
| | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges… | May 12, 2026 | Aug 10, 2026 |
| | CVE-2026-40418 | Microsoft | high | 7.8 | 0.0%
| | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-40419 | Microsoft | high | 7.8 | 0.0%
| | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | May 12, 2026 | May 19, 2026 |
| | CVE-2026-40420 | Microsoft | high | 8.8 | 0.0%
| | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-40421 | Microsoft | medium | 4.3 | 0.1%
| | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized … | May 12, 2026 | Jun 1, 2026 |
| | CVE-2026-41086 | Microsoft | high | 8.8 | 0.1%
| | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges … | May 12, 2026 | May 15, 2026 |
| | CVE-2026-41094 | Microsoft | high | 8.8 | 0.1%
| | Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an una… | May 12, 2026 | May 16, 2026 |
| | CVE-2026-41100 | Microsoft | medium | 4.4 | 0.0%
| | Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | May 12, 2026 | May 16, 2026 |
| | CVE-2026-41101 | Microsoft | high | 7.1 | 0.0%
| | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing l… | May 12, 2026 | May 16, 2026 |
| | CVE-2026-41102 | Microsoft | high | 7.1 | 0.0%
| | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoo… | May 12, 2026 | May 16, 2026 |
| | CVE-2026-41103 | Microsoft | critical | 9.1 | 0.1%
| | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluen… | May 12, 2026 | May 16, 2026 |
| | CVE-2026-41107 | Microsoft | high | 7.4 | 0.1%
| | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized atta… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-41109 | Microsoft | high | 8.8 | 0.9%
| | Improper neutralization of special elements in output used by a downstream component ('injection') i… | May 12, 2026 | Aug 10, 2026 |
| | CVE-2026-41610 | Microsoft | medium | 6.3 | 0.0%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studi… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-41611 | Microsoft | high | 7.8 | 0.0%
| | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code … | May 12, 2026 | May 15, 2026 |
| | CVE-2026-41612 | Microsoft | medium | 5.5 | 0.0%
| | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose informatio… | May 12, 2026 | May 15, 2026 |
| | CVE-2026-41613 | Microsoft | high | 8.8 | 0.1%
| | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a … | May 12, 2026 | May 15, 2026 |
| | CVE-2026-41614 | Microsoft | medium | 6.2 | 0.0%
| | Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoof… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-42823 | Microsoft | critical | 9.9 | 0.1%
| | Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-42830 | Microsoft | medium | 6.5 | 0.1%
| | Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges loc… | May 12, 2026 | May 14, 2026 |
| | CVE-2026-42831 | Microsoft | high | 7.8 | 0.1%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | May 12, 2026 | May 19, 2026 |
| | CVE-2026-42832 | Microsoft | high | 7.7 | 0.0%
| | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing loca… | May 12, 2026 | May 19, 2026 |