microsoft has 2,953 CVEs on record between 2013 and 2026. Disclosure cadence is accelerating: 2137 in the last 90 days against 419 in the 90 before. The busiest recent month was September 2026 with 1005. The median CVSS is 7.8 (high), with 178 rated critical. 3% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 113 days (91 cases). The dominant weakness classes are CWE-122 (585) and CWE-416 (512). Most affected products: windows_10_1607 (644), Windows 10 Version 1607 (481), Microsoft 365 Apps for Enterprise (209).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 3% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- 113 d median(91)
- Last 90 days
- 2137 prev 419
Weakness classes
Products
- windows_10_1607 644
- Windows 10 Version 1607 481
- Microsoft 365 Apps for Enterprise 209
- windows_10 122
- 365_apps 115
- windows_10_1809 106
Worst active — by depth score
CVE-2025-53770Critical· 9.8Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…100CVE-2021-38647Critical· 9.8Open Management Infrastructure (OMI) Remote Code Execution Vulnerability100CVE-2021-34473Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability100CVE-2021-26855Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability100CVE-2020-0796Critical· 10.0A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.100
microsoft vulnerabilities
CVEs affecting microsoft, newest first. Open any entry for full detail, references, and exploit status.
2953 CVEsRSS
CVE-2026-66313Medium· 6.8Microsoft Edge (Chromium-based) Tampering Vulnerability
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66312Medium· 6.5Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-66325Medium· 6.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66317Medium· 5.4Microsoft Edge (Chromium-based) Tampering Vulnerability
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
CVE-2026-66311Medium· 6.2Microsoft Edge (Chromium-based) Tampering Vulnerability
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-65804Medium· 6.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-65802High· 7.4Microsoft Edge for Android Information Disclosure Vulnerability
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
CVE-2026-66326Medium· 6.5Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66322High· 7.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66803Critical· 10.0Azure Cosmos DB Remote Code Execution Vulnerability
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2026-62828Medium· 5.4Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.
CVE-2026-57990High· 7.4Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-57989High· 7.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-57978Medium· 5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-56163Critical· 10.0Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50517Critical· 9.9Microsoft M365 Copilot Remote Code Execution Vulnerability
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-49159Medium· 6.5Microsoft Graph Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
CVE-2026-35425High· 8.0Azure API Management (APIM) Remote Code Execution Vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-62835Critical· 9.3Azure Portal Information Disclosure Vulnerability
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-57106Critical· 10.0Data Quality Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56191Critical· 10.0Microsoft Exchange Online Tampering Vulnerability
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-58630Critical· 10.0Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825Critical· 10.0Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275Critical· 10.0Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56160Critical· 9.1Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVE-2026-59860HighMicrosoft Kiota: XML Doc-Comment Newline Breakout Code Injection
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
CVE-2026-59861High· 7.5Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
CVE-2026-59862High· 7.5Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
CVE-2026-59859HighMicrosoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
CVE-2026-59864CriticalMicrosoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions