VulnSea

microsoft has 2,953 CVEs on record between 2013 and 2026. Disclosure cadence is accelerating: 2137 in the last 90 days against 419 in the 90 before. The busiest recent month was September 2026 with 1005. The median CVSS is 7.8 (high), with 178 rated critical. 3% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 113 days (91 cases). The dominant weakness classes are CWE-122 (585) and CWE-416 (512). Most affected products: windows_10_1607 (639), Windows 10 Version 1607 (486), Microsoft 365 Apps for Enterprise (209).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
7.8
Publish → KEV
113 d median(91)
Last 90 days
2137 prev 419

Products

  • windows_10_1607 639
  • Windows 10 Version 1607 486
  • Microsoft 365 Apps for Enterprise 209
  • windows_10 122
  • 365_apps 115
  • windows_10_1809 106
2953
Total CVEs
178
Critical
91
CISA KEV
92
Exploited

Microsoft vulnerabilities

CVEs affecting Microsoft, newest first. Open any entry for full detail, references, and exploit status.

2953 CVEsRSS

CVE-2026-69558High· 8.6
1mo ago

Microsoft Partner Center Information Disclosure Vulnerability

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Partner CenterEPSS 0.97%via CVEORG
CVE-2026-69543High· 8.5
1mo ago

Azure Virtual Machines Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure Virtual MachinesEPSS 0.56%via CVEORG
CVE-2026-69855High· 7.7
1mo ago

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

▾ Twilightmicrosoft · azure_copilotEPSS 0.84%via NVD
CVE-2026-68789Critical· 9.9
1mo ago

Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure SQL DatabaseEPSS 0.99%via CVEORG
CVE-2026-65801Critical· 10.0
1mo ago

Microsoft Exchange Online Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.90%via CVEORG
CVE-2026-62834Critical· 9.3
1mo ago

Azure Data Factory Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Data FactoryEPSS 0.53%via CVEORG
CVE-2026-55015Medium· 5.5
1mo ago

Microsoft Remote Help Denial of Service Vulnerability

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

▾ SunlitMicrosoft · Windows Remote HelpEPSS 0.98%via CVEORG
CVE-2026-55013High· 7.1
1mo ago

Windows Remote Help Defense Spoofing Vulnerability

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

▾ TwilightMicrosoft · Windows Remote HelpEPSS 0.46%via CVEORG
CVE-2026-68782Critical· 9.9
1mo ago

Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure SQL DatabaseEPSS 0.99%via CVEORG
CVE-2026-66800High· 8.6
1mo ago

Azure Data Factory Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Azure Data FactoryEPSS 0.97%via CVEORG
CVE-2026-65816Critical· 10.0
1mo ago

Azure Arc Elevation of Privilege Vulnerability

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Web AppsEPSS 0.97%via CVEORG
CVE-2026-65770Critical· 10.0
1mo ago

Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Azure Managed Instance for Apache CassandraEPSS 1.1%via CVEORG
CVE-2026-63509Critical· 9.9
1mo ago

Microsoft Fabric Elevation of Privilege Vulnerability

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft FabricEPSS 1.0%via CVEORG
CVE-2026-69419High· 8.5
1mo ago

Azure Data Manager for Energy Remote Code Execution Vulnerability

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Azure Data Manager for EnergyEPSS 0.74%via CVEORG
CVE-2026-69400Critical· 9.6
1mo ago

Azure Logic Apps Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Logic AppsEPSS 0.94%via CVEORG
CVE-2026-66309Critical· 9.1
1mo ago

Azure SQL Database Elevation of Privilege Vulnerability

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure SQL DatabaseEPSS 0.86%via CVEORG
CVE-2026-69550Medium· 6.5
1mo ago

Windows App for Mac Information Disclosure Vulnerability

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Windows App for MacEPSS 0.92%via CVEORG
CVE-2026-62727High· 7.0
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-24301High· 8.8PoC
1mo ago

Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

▾ MidnightMicrosoft · Copilot WebEPSS 4.1%via CVEORG
CVE-2026-72970High· 8.3
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.73%via CVEORG
CVE-2026-69414High· 7.8PoC
1mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".

▾ MidnightMicrosoft · Microsoft Malware Protection EngineEPSS 0.33%via CVEORG
CVE-2026-50523High· 7.8
1mo ago

Microsoft PowerShell Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · PowerShell 7.4EPSS 0.32%via CVEORG
CVE-2026-73299Critical· 10.0
1mo ago

Prompty is a markdown file format (.prompty) for LLM prompts

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controll…

▾ Midnightmicrosoft · promptyEPSS 1.8%via NVD
GHSA-2q33-cf8w-7q23Critical· 9.8
1mo ago

Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability

Duplicate Advisory: Microsoft QUIC Remote Code Execution Vulnerability

▾ MidnightMicrosoft · Microsoft.Native.Quic.MsQuic.OpenSSLvia GHSA
CVE-2026-70307High· 7.0
1mo ago

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.26%via CVEORG
CVE-2026-70340High· 8.1
1mo ago

Azure CycleCloud Elevation of Privilege Vulnerability

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure CycleCloud 8.9.1EPSS 0.80%via CVEORG
CVE-2026-70330Medium· 6.7
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.34%via CVEORG
CVE-2026-70329High· 8.8
1mo ago

Microsoft Outlook Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.82%via CVEORG
CVE-2026-70328Medium· 6.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.92%via CVEORG
CVE-2026-70327Medium· 6.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.92%via CVEORG
Microsoft vulnerabilities (CVEs) — page 35 · VulnSea