| | CVE-2026-50355 | Microsoft | high | 7.5 | 1.1%
| | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker … | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50314 | Microsoft | high | 7.8 | 0.4%
| | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50301 | Microsoft | high | 7.8 | 0.3%
| | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-48580 | Microsoft | medium | 5.5 | 0.5%
| | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-47642 | Microsoft | high | 7.8 | 0.4%
| | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-47295 | Microsoft | high | 8.8 | 0.9%
| | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a… | Jul 14, 2026 | Jul 22, 2026 |
| | CVE-2026-47290 | Microsoft | high | 7.8 | 0.4%
| | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-58647 | Microsoft | high | 8.0 | 0.3%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI all… | Jul 14, 2026 | Aug 19, 2026 |
| | CVE-2026-58644 | Microsoft | critical | 9.8 | 1.3%
| ⚠ KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to … | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-58636 | Microsoft | high | 7.8 | 0.3%
| | Improper link resolution before file access ('link following') in Window PC Manager allows an author… | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-58631 | Microsoft | high | 7.8 | 0.3%
| | Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally… | Jul 14, 2026 | Jul 17, 2026 |
| | CVE-2026-58618 | Microsoft | high | 7.8 | 0.3%
| | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-58595 | Microsoft | high | 8.1 | 0.5%
| | Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unautho… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-58279 | Microsoft | medium | 6.5 | 0.4%
| | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a… | Jul 14, 2026 | Jul 22, 2026 |
| | CVE-2026-57969 | Microsoft | high | 8.8 | 0.5%
| | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to el… | Jul 14, 2026 | Jul 22, 2026 |
| | CVE-2026-57107 | Microsoft | high | 7.8 | 0.2%
| | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges … | Jul 14, 2026 | Jul 21, 2026 |
| | CVE-2026-56193 | Microsoft | high | 7.1 | 0.4%
| | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-56185 | Microsoft | medium | 6.5 | 0.6%
| | Improper authentication in Windows Admin Center allows an authorized attacker to disclose informatio… | Jul 14, 2026 | Jul 21, 2026 |
| | CVE-2026-56170 | Microsoft | high | 7.5 | 0.8%
| | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker… | Jul 14, 2026 | Jul 22, 2026 |
| | CVE-2026-56169 | Microsoft | high | 8.1 | 0.5%
| | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges … | Jul 14, 2026 | Jul 21, 2026 |
| | CVE-2026-56164 | Microsoft | medium | 5.3 | — | ⚠ KEV | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized a… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-55948 | Microsoft | high | 7.8 | 0.3%
| | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-55899 | Microsoft | high | 7.8 | 0.3%
| | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute cod… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-55014 | Microsoft | high | 7.8 | 0.2%
| | Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate priv… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-55012 | Microsoft | high | 7.8 | 0.4%
| | Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-55011 | Microsoft | high | 7.8 | 0.4%
| | Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to exec… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-55009 | Microsoft | high | 7.8 | 1.6%
| | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elev… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-55008 | Microsoft | critical | 9.6 | 0.9%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-55006 | Microsoft | high | 7.8 | 0.2%
| | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacke… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-55005 | Microsoft | high | 8.8 | 0.7%
| | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute cod… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-55002 | Microsoft | high | 8.8 | 0.2%
| | External control of file name or path in SQL Server allows an authorized attacker to elevate privile… | Jul 14, 2026 | Aug 4, 2026 |
| | CVE-2026-54988 | Microsoft | medium | 6.1 | 0.3%
| | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-54118 | Microsoft | critical | 9.8 | 1.2%
| | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over… | Jul 14, 2026 | Aug 20, 2026 |
| | CVE-2026-54117 | Microsoft | critical | 9.8 | 1.2%
| | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over… | Jul 14, 2026 | Aug 20, 2026 |
| | CVE-2026-54108 | Microsoft | medium | 6.5 | 0.7%
| | External control of file name or path in Microsoft Office SharePoint allows an authorized attacker t… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50678 | Microsoft | medium | 6.6 | 0.3%
| | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose inf… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50675 | Microsoft | high | 7.8 | 0.3%
| | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-50663 | Microsoft | high | 8.8 | 0.7%
| | Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacke… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50653 | Microsoft | high | 7.5 | 0.8%
| | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthori… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50652 | Microsoft | high | 7.5 | 1.1%
| | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny … | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50522 | Microsoft | critical | 9.8 | 21.0%
| ⚠ KEV | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to … | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-50520 | Microsoft | high | 8.4 | 0.6%
| | Improper neutralization of special elements used in a command ('command injection') in Visual Studio… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-50506 | Microsoft | high | 7.5 | 0.8%
| | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50338 | Microsoft | high | 8.2 | 0.5%
| | Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges ove… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-48561 | Microsoft | critical | 9.6 | 0.8%
| | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat … | Jul 14, 2026 | Jul 26, 2026 |
| | CVE-2026-47632 | Microsoft | high | 8.8 | 0.3%
| | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to … | Jul 14, 2026 | Aug 18, 2026 |
| | CVE-2026-47296 | Microsoft | high | 7.5 | 0.2%
| | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a… | Jul 14, 2026 | Aug 4, 2026 |
| | CVE-2026-47282 | Microsoft | medium | 6.5 | 0.6%
| | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-45646 | Microsoft | high | 7.5 | 0.8%
| | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-45496 | Microsoft | medium | 5.5 | 0.5%
| | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code… | Jul 14, 2026 | Jul 16, 2026 |