VulnSea

microsoft has 2,953 CVEs on record between 2013 and 2026. Disclosure cadence is accelerating: 2137 in the last 90 days against 419 in the 90 before. The busiest recent month was September 2026 with 1005. The median CVSS is 7.8 (high), with 178 rated critical. 3% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 113 days (91 cases). The dominant weakness classes are CWE-122 (585) and CWE-416 (512). Most affected products: windows_10_1607 (639), Windows 10 Version 1607 (486), Microsoft 365 Apps for Enterprise (209).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
7.8
Publish → KEV
113 d median(91)
Last 90 days
2137 prev 419

Products

  • windows_10_1607 639
  • Windows 10 Version 1607 486
  • Microsoft 365 Apps for Enterprise 209
  • windows_10 122
  • 365_apps 115
  • windows_10_1809 106
2953
Total CVEs
178
Critical
91
CISA KEV
92
Exploited

Microsoft vulnerabilities

CVEs affecting Microsoft, newest first. Open any entry for full detail, references, and exploit status.

2953 CVEsRSS

CVE-2026-62697High· 7.8
2w ago

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_21h2EPSS 0.33%via NVD
CVE-2026-56172High· 7.8
2w ago

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.33%via NVD
CVE-2026-58599High· 7.8
2w ago

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · HEVC Video ExtensionsEPSS 0.48%via NVD
CVE-2026-47297High· 8.1
2w ago

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SQL Server 2019 (CU 32)EPSS 1.1%via NVD
CVE-2026-58649Medium· 6.5
2w ago

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.27%via NVD
CVE-2026-57099High· 7.5
2w ago

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · AspNetCore.ODataEPSS 1.2%via NVD
CVE-2026-62804High· 7.8
2w ago

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

▾ Twilightmicrosoft · 365_appsEPSS 0.61%via NVD
CVE-2026-69857High· 8.5
3w ago

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · azure_cosmos_dbEPSS 0.63%via NVD
CVE-2026-62906High· 7.4
3w ago

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Discovery StudioEPSS 0.94%via NVD
CVE-2026-83711Critical· 10.0
3w ago

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · EntraEPSS 0.81%via NVD
CVE-2026-80098Critical· 9.3
3w ago

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · copilot_studioEPSS 0.49%via NVD
CVE-2026-70352Critical· 10.0
3w ago

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure AI Language AuthoringEPSS 0.92%via NVD
CVE-2026-70178High· 8.5
3w ago

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · fabricEPSS 0.63%via NVD
CVE-2026-65818High· 8.5
3w ago

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · power_platformEPSS 0.63%via NVD
CVE-2026-62916Critical· 9.1
3w ago

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · entra_idEPSS 0.86%via NVD
CVE-2026-66324Medium· 6.5
1mo ago

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.92%via NVD
CVE-2026-66798Medium· 4.3
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.79%via CVEORG
CVE-2026-62904Medium· 5.4
1mo ago

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.39%via NVD
CVE-2026-58616Medium· 4.4
1mo ago

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.29%via CVEORG
CVE-2026-70331Medium· 5.4
1mo ago

Microsoft Edge for iOS Spoofing Vulnerability

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.41%via CVEORG
CVE-2026-70309Medium· 5.4
1mo ago

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.21%via CVEORG
CVE-2026-72984High· 8.8
1mo ago

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · edge_chromiumEPSS 0.82%via NVD
CVE-2026-66323Medium· 5.4
1mo ago

Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.41%via NVD
CVE-2026-62316High· 8.8PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate t…

▾ Midnightmicrosoft · UFOEPSS 0.51%via NVD
CVE-2026-69502Critical· 10.0
1mo ago

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_sql_databaseEPSS 0.80%via NVD
CVE-2026-69851Critical· 9.9
1mo ago

Microsoft Entra ID Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft EntraEPSS 0.78%via CVEORG
CVE-2026-69836Critical· 10.0PoC
1mo ago

Microsoft Entra ID Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

▾ AbyssalMicrosoft · Microsoft EntraEPSS 1.5%via CVEORG
CVE-2026-69519High· 8.6
1mo ago

Azure Stack HCI Information Disclosure Vulnerability

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Azure Stack HCIEPSS 1.0%via CVEORG
CVE-2026-70105Medium· 6.5
1mo ago

Microsoft Word Information Disclosure Vulnerability

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.97%via CVEORG
CVE-2026-69555Critical· 10.0
1mo ago

Azure Arc Elevation of Privilege Vulnerability

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure ARCEPSS 0.80%via CVEORG
Microsoft vulnerabilities (CVEs) — page 34 · VulnSea