Release roundup
Microsoft Patch Tuesday, August 2026: two exploited flaws headline 375 CVEs
Microsoft Patch Tuesday, August 2026 covers 375 CVEs — 5 critical, 246 high, 124 medium. Two are exploited and in CISA KEV: a SharePoint Server RCE and a Windows AFD WinSock elevation of privilege. Patch those first, then exposed network-facing critical services.
The release at a glance
Microsoft's August 2026 Patch Tuesday release is in scope for 375 CVEs, made up of 5 critical, 246 high and 124 medium. Two vulnerabilities are the standout items because both are in CISA KEV. CVE-2026-65660 is a Microsoft SharePoint Server remote code execution vulnerability added to KEV on 25 September 2026 with a due date of 28 September 2026; CVE-2026-68820 is a Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability added on 11 August 2026 with a due date of 25 August 2026. Microsoft also flags CVE-2026-68820 as exploited; for CVE-2026-65660, CISA KEV is the source that lists it as exploited. The rest of the release is a large set of Windows, SharePoint, Microsoft 365 Apps, Edge and Exchange updates, with several critical network-facing remote code execution flaws.
What matters most
For SharePoint, CVE-2026-65660 is the first to review: an improper code injection flaw in Microsoft Office SharePoint that allows an authorised attacker to execute code over the network. CISA KEV lists it as exploited, and fixed versions are SharePoint Enterprise Server 2016 16.0.5565.1001, SharePoint Server 2019 16.0.10417.20198 and SharePoint Server Subscription Edition 16.0.19725.20522. CVE-2026-70306 is a SharePoint spoofing issue caused by improper neutralisation of input; it is rated critical at 9.3, reachable over the network without authentication but requiring user interaction. CVE-2026-63514 is a deserialisation-of-untrusted-data remote code execution flaw rated 8.8, and it sits alongside CVE-2026-64901, CVE-2026-65658, CVE-2026-65663 and CVE-2026-66805 with the same SharePoint fix profile.
For Windows and Windows Server, CVE-2026-68820 is a use-after-free elevation of privilege in the Windows Ancillary Function Driver for WinSock. CISA KEV, CISA SSVC and Microsoft flag it as exploited; it affects Windows 10, Windows 11 and Windows Server 2012 through 2025. CVE-2026-62815 is a use-after-free remote code execution in Microsoft QUIC rated 9.8, reachable over the network without authentication, affecting Windows 11 and Windows Server 2022 and 2025. CVE-2026-62878 is a stack-based buffer overflow in Windows DNS Server rated 9.8 with the same pre-authentication exposure, affecting Windows Server 2012 through 2025. CVE-2026-62893 is a use-after-free remote code execution in Windows Deployment Services TFTP Server rated 9.8 and reachable pre-authentication. CVE-2026-65791 is a heap-based buffer overflow in Windows iSCSI Target Service rated 9.8 and reachable pre-authentication; it affects Windows 10 Version 1607, Windows 10 Version 1809 and Windows Server 2012 through 2025.
Patch in this order
- Patch the two exploited items first. For CVE-2026-65660, apply the SharePoint fixed versions listed above by CISA's due date of 28 September 2026. For CVE-2026-68820, apply the August Windows security updates on all affected Windows 10, Windows 11 and Windows Server systems; examples of fixed versions include Windows 10 22H2 10.0.19045.7663, Windows 11 24H2 10.0.26100.9168 and Windows Server 2022 10.0.20348.5499. CISA's due date for CVE-2026-68820 is 25 August 2026.
- Patch the critical network-facing remote code execution flaws next, especially on internet-exposed services: CVE-2026-62815 (Microsoft QUIC), CVE-2026-62878 (Windows DNS Server), CVE-2026-62893 (Windows Deployment Services TFTP Server) and CVE-2026-65791 (Windows iSCSI Target Service). These are all rated 9.8 and reachable pre-authentication. Apply the August cumulative updates for affected Windows and Windows Server versions, such as Windows Server 2022 10.0.20348.5499.
- Update SharePoint for the remaining SharePoint issues — CVE-2026-70306, CVE-2026-63514, CVE-2026-64901, CVE-2026-65658, CVE-2026-65663 and CVE-2026-66805 — using the same fixed versions as CVE-2026-65660.
- Roll out the remaining high and medium vulnerabilities as a normal patch cycle, giving priority to any product that is exposed to untrusted networks.
Beyond the patch
A release of 375 CVEs is manageable if you separate the two exploited items from the critical network-facing group and from everything else. Managed Detection & Response (MDR) helps with the exploited SharePoint and Windows flaws, while Virtual CISO Services (vCISO) can turn the QUIC, DNS, Deployment Services and iSCSI remote code execution issues into a clear list of what is actually exposed, so the first patch run is proportionate.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-65660 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 KEV | |
| CVE-2026-68820 | Windows 10 Version 1607 | High 7.0 KEV | |
| CVE-2026-62815 | Windows 11 version 23H2 | Critical 9.8 | |
| CVE-2026-62878 | Windows Server 2012 | Critical 9.8 | |
| CVE-2026-62893 | Windows Server 2012 | Critical 9.8 | |
| CVE-2026-65791 | Windows 10 Version 1607 | Critical 9.8 | |
| CVE-2026-70306 | Microsoft SharePoint Enterprise Server 2016 | Critical 9.3 | |
| CVE-2026-63514 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-64901 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-65658 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-65663 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-66805 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-66808 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-65665 | Microsoft SharePoint Server 2019 | High 8.8 | |
| CVE-2026-70321 | Microsoft SharePoint Server Subscription Edition | High 8.8 | |
| CVE-2026-49179 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62784 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62790 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62800 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62818 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62827 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-62913 | Microsoft Exchange Server 2016 Cumulative Update 23 | High 8.8 | |
| CVE-2026-64921 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-65768 | Microsoft Teams for Android | High 8.8 | |
| CVE-2026-65811 | Power BI Report Server | High 8.8 | |
| CVE-2026-70324 | Microsoft SharePoint Enterprise Server 2016 | High 8.8 | |
| CVE-2026-62785 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62795 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62816 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62817 | Windows Server 2019 | High 8.8 | |
| CVE-2026-62822 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-62823 | Windows Server 2012 | High 8.8 | |
| CVE-2026-62824 | Windows 10 Version 1607 | High 8.8 | |
| CVE-2026-65767 | Microsoft Teams for Android | High 8.8 | |
| CVE-2026-65807 | Microsoft 365 Apps for Enterprise | High 8.8 | |
| CVE-2026-70326 | Microsoft SharePoint Server Subscription Edition | High 8.8 | |
| CVE-2026-70329 | Microsoft 365 Apps for Enterprise | High 8.8 | |
| CVE-2026-72984 | Microsoft Edge (Chromium-based) | High 8.8 | |
| CVE-2026-70341 | Microsoft Edge (Chromium-based) | High 8.5 | |
| CVE-2026-70130 | Microsoft 365 Apps for Enterprise | High 8.4 |
Show all 375
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-72970 | Microsoft Edge (Chromium-based) | High 8.3 | |
| CVE-2026-56179 | Windows 11 Version 24H2 | High 8.3 | |
| CVE-2026-63520 | Microsoft SharePoint Enterprise Server 2016 | High 8.1 | |
| CVE-2026-62778 | Windows 10 Version 1607 | High 8.1 | |
| CVE-2026-62781 | Windows 10 Version 1607 | High 8.1 | |
| CVE-2026-62792 | Windows 10 Version 1607 | High 8.1 | |
| CVE-2026-62819 | Windows 10 Version 1607 | High 8.1 | |
| CVE-2026-62820 | Windows Server 2016 | High 8.1 | |
| CVE-2026-62889 | Windows 10 Version 1607 | High 8.1 | |
| CVE-2026-65679 | Windows 10 Version 1607 | High 8.1 | |
| CVE-2026-65789 | Windows Server 2016 | High 8.1 | |
| CVE-2026-65796 | Windows 10 Version 1607 | High 8.1 | |
| CVE-2026-66802 | Windows 10 Version 1809 | High 8.1 | |
| CVE-2026-71331 | Windows 10 Version 1809 | High 8.1 | |
| CVE-2026-57105 | Microsoft SharePoint Server 2019 | High 8.0 | |
| CVE-2026-62911 | Microsoft Exchange Server 2016 Cumulative Update 23 | High 8.0 | |
| CVE-2026-42976 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-54984 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-56174 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-58651 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-59127 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61349 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61353 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61355 | Windows 10 Version 21H2 | High 7.8 | |
| CVE-2026-61356 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-61357 | Windows 11 Version 24H2 | High 7.8 | |
| CVE-2026-61358 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-61359 | Windows 11 version 23H2 | High 7.8 | |
| CVE-2026-61364 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61365 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61367 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61923 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-61925 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61926 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61930 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61932 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-61934 | Windows 11 version 23H2 | High 7.8 | |
| CVE-2026-61937 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62688 | Windows 11 Version 24H2 | High 7.8 | |
| CVE-2026-62692 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62695 | Windows 11 version 23H2 | High 7.8 | |
| CVE-2026-62696 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62698 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62700 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62701 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62707 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62710 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62711 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62712 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62713 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-62717 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62719 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62721 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62722 | Windows 11 Version 24H2 | High 7.8 | |
| CVE-2026-62732 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62733 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62735 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62736 | Windows 11 version 23H2 | High 7.8 | |
| CVE-2026-62737 | Windows 11 Version 24H2 | High 7.8 | |
| CVE-2026-62739 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-62741 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62747 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62751 | Windows 10 Version 21H2 | High 7.8 | |
| CVE-2026-62752 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62754 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62755 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62758 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62761 | Windows Server 2012 | High 7.8 | |
| CVE-2026-62768 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62770 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62771 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-62772 | Windows 11 version 26H1 | High 7.8 | |
| CVE-2026-62776 | Windows Server 2012 | High 7.8 | |
| CVE-2026-62777 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62779 | Windows 11 Version 24H2 | High 7.8 | |
| CVE-2026-62783 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-62797 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62799 | Windows 11 version 26H1 | High 7.8 | |
| CVE-2026-62803 | Windows Server 2012 | High 7.8 | |
| CVE-2026-62807 | Windows Server 2012 | High 7.8 | |
| CVE-2026-62811 | Windows 11 version 23H2 | High 7.8 | |
| CVE-2026-62812 | Windows Server 2012 | High 7.8 | |
| CVE-2026-62832 | Windows 10 Version 21H2 | High 7.8 | |
| CVE-2026-62876 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62877 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62880 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62885 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62888 | Windows 10 Version 21H2 | High 7.8 | |
| CVE-2026-62890 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-62894 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-63513 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63515 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63518 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63519 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63525 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63526 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63527 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63532 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-63533 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64898 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64903 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64904 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64905 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64906 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64907 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64908 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64909 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64910 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64911 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64912 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64914 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64915 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64919 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-64920 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-65656 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-65657 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-65661 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-65664 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-65671 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-65672 | Windows 11 version 23H2 | High 7.8 | |
| CVE-2026-65773 | Windows 10 Version 1809 | High 7.8 | |
| CVE-2026-65774 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-65775 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-65786 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-65787 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-65790 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-65814 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-66799 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-66804 | Windows 10 Version 22H2 | High 7.8 | |
| CVE-2026-66807 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68792 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68793 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68794 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68795 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68796 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68798 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68800 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68801 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68803 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68804 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68805 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68806 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68807 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68810 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68811 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68812 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68814 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68815 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68816 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-68817 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-70311 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-70313 | Microsoft 365 Apps for Enterprise | High 7.8 | |
| CVE-2026-70344 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-70345 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-70346 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-70347 | Windows 10 Version 1607 | High 7.8 | |
| CVE-2026-54113 | Windows 10 Version 1607 | High 7.5 | |
| CVE-2026-59132 | Windows 10 Version 1607 | High 7.5 | |
| CVE-2026-65681 | Windows 10 Version 1607 | High 7.5 | |
| CVE-2026-59134 | Windows 10 Version 1607 | High 7.5 | |
| CVE-2026-61363 | Windows 10 Version 1607 | High 7.5 | |
| CVE-2026-62787 | Windows Server 2012 | High 7.5 | |
| CVE-2026-61352 | Windows 10 Version 1607 | High 7.5 | |
| CVE-2026-64900 | Microsoft SharePoint Enterprise Server 2016 | High 7.3 | |
| CVE-2026-70355 | Microsoft SharePoint Server 2019 | High 7.3 | |
| CVE-2026-62914 | Microsoft Exchange Server 2016 Cumulative Update 23 | High 7.3 | |
| CVE-2026-62910 | Microsoft Exchange Server 2016 Cumulative Update 23 | High 7.2 | |
| CVE-2026-55013 | Windows Remote Help | High 7.1 | |
| CVE-2026-50472 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-59122 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-59125 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-59126 | Windows 10 Version 21H2 | High 7.0 | |
| CVE-2026-61346 | Windows 10 Version 1809 | High 7.0 | |
| CVE-2026-61348 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-61361 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-61366 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-61927 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-61929 | Windows 11 version 23H2 | High 7.0 | |
| CVE-2026-61938 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-61939 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62690 | Windows 10 Version 1809 | High 7.0 | |
| CVE-2026-62693 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-62705 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-62723 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62724 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62725 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62726 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62727 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62728 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62729 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62734 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62748 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62749 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-62753 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62766 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-62773 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62774 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62780 | Windows 11 version 23H2 | High 7.0 | |
| CVE-2026-62788 | Windows 11 version 23H2 | High 7.0 | |
| CVE-2026-62892 | Windows 10 Version 1809 | High 7.0 | |
| CVE-2026-62908 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-65678 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-65776 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-65778 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-65779 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-65780 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-65781 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-65782 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-65783 | Windows 11 Version 24H2 | High 7.0 | |
| CVE-2026-65788 | Windows 11 version 23H2 | High 7.0 | |
| CVE-2026-70307 | Windows 10 Version 1607 | High 7.0 | |
| CVE-2026-62702 | Windows 10 Version 21H2 | Medium 6.8 | |
| CVE-2026-62699 | Windows 10 Version 1607 | Medium 6.8 | |
| CVE-2026-62769 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-62881 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-62883 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-65680 | OneDrive for MacOS | Medium 6.7 | |
| CVE-2026-65795 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-65797 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-65798 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-65799 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-70304 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-70330 | Windows 10 Version 1607 | Medium 6.7 | |
| CVE-2026-61920 | Windows Server 2012 R2 | Medium 6.6 | |
| CVE-2026-62912 | Microsoft Exchange Server 2016 Cumulative Update 23 | Medium 6.5 | |
| CVE-2026-63516 | Microsoft SharePoint Enterprise Server 2016 | Medium 6.5 | |
| CVE-2026-62837 | Microsoft SharePoint Enterprise Server 2016 | Medium 6.5 | |
| CVE-2026-58639 | Microsoft SharePoint Enterprise Server 2016 | Medium 6.5 | |
| CVE-2026-59138 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-61345 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-61918 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-61921 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-61924 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-62782 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-62839 | Microsoft SharePoint Enterprise Server 2016 | Medium 6.5 | |
| CVE-2026-65769 | Microsoft Teams for iOS | Medium 6.5 | |
| CVE-2026-65794 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-65813 | Microsoft Exchange Server 2016 Cumulative Update 23 | Medium 6.5 | |
| CVE-2026-66324 | Microsoft Edge for Android | Medium 6.5 | |
| CVE-2026-69550 | Windows App for Mac | Medium 6.5 | |
| CVE-2026-70105 | Microsoft 365 Apps for Enterprise | Medium 6.5 | |
| CVE-2026-70327 | Microsoft 365 Apps for Enterprise | Medium 6.5 | |
| CVE-2026-70328 | Microsoft 365 Apps for Enterprise | Medium 6.5 | |
| CVE-2026-62714 | Windows Server 2012 | Medium 6.5 | |
| CVE-2026-62715 | Windows Server 2012 R2 | Medium 6.5 | |
| CVE-2026-62716 | Windows Server 2012 | Medium 6.5 | |
| CVE-2026-62718 | Windows Server 2012 | Medium 6.5 | |
| CVE-2026-62720 | Windows Server 2012 | Medium 6.5 | |
| CVE-2026-62742 | Windows Server 2012 | Medium 6.5 | |
| CVE-2026-62745 | Windows Server 2012 | Medium 6.5 | |
| CVE-2026-62750 | Windows 10 Version 1607 | Medium 6.5 | |
| CVE-2026-62814 | Windows Server 2012 | Medium 6.5 | |
| CVE-2026-62915 | Microsoft Exchange Server 2016 Cumulative Update 23 | Medium 6.5 | |
| CVE-2026-63512 | Microsoft SharePoint Enterprise Server 2016 | Medium 6.5 | |
| CVE-2026-65785 | Windows 11 Version 24H2 | Medium 6.5 | |
| CVE-2026-62708 | Windows 11 Version 24H2 | Medium 6.4 | |
| CVE-2026-68819 | Windows 10 Version 1607 | Medium 5.9 | |
| CVE-2026-59130 | Windows 10 Version 1607 | Medium 5.6 | |
| CVE-2026-59131 | Windows 10 Version 1607 | Medium 5.6 | |
| CVE-2026-55015 | Windows Remote Help | Medium 5.5 | |
| CVE-2026-62842 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-63517 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-63524 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-63528 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-63529 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-63530 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-63531 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-64899 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-64917 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-68797 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-68799 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-68802 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-68808 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-68813 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70314 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70318 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-59128 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-59135 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-59136 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-59137 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-61347 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-61360 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-61928 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-61933 | Windows 11 Version 24H2 | Medium 5.5 | |
| CVE-2026-61936 | Windows 10 Version 1809 | Medium 5.5 | |
| CVE-2026-62703 | Windows 10 Version 1809 | Medium 5.5 | |
| CVE-2026-62709 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62730 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62738 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62740 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62743 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62746 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62775 | Windows 11 version 26H1 | Medium 5.5 | |
| CVE-2026-62786 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62793 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62796 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-62798 | Windows 11 version 23H2 | Medium 5.5 | |
| CVE-2026-62887 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-63521 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-65662 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-65784 | Windows 10 Version 1607 | Medium 5.5 | |
| CVE-2026-66806 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-66809 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-66810 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-68809 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70310 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70312 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70315 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70316 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70317 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70319 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70320 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70322 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70323 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70325 | Microsoft 365 Apps for Enterprise | Medium 5.5 | |
| CVE-2026-70348 | Windows 11 Version 24H2 | Medium 5.5 | |
| CVE-2026-72971 | Windows 11 version 26H1 | Medium 5.5 | |
| CVE-2026-62904 | Microsoft Edge (Chromium-based) | Medium 5.4 | |
| CVE-2026-66323 | Microsoft Edge for Android | Medium 5.4 | |
| CVE-2026-70309 | Microsoft Edge (Chromium-based) | Medium 5.4 | |
| CVE-2026-70331 | Microsoft Edge (Chromium-based) | Medium 5.4 | |
| CVE-2026-70339 | Microsoft Edge (Chromium-based) | Medium 5.4 | |
| CVE-2026-62757 | Windows 10 Version 1607 | Medium 5.3 | |
| CVE-2026-65777 | Windows 11 version 23H2 | Medium 5.3 | |
| CVE-2026-61368 | Windows 10 Version 1607 | Medium 5.0 | |
| CVE-2026-62917 | Microsoft SharePoint Enterprise Server 2016 | Medium 4.6 | |
| CVE-2026-64897 | Microsoft SharePoint Enterprise Server 2016 | Medium 4.6 | |
| CVE-2026-64902 | Microsoft SharePoint Enterprise Server 2016 | Medium 4.6 | |
| CVE-2026-64916 | Microsoft SharePoint Enterprise Server 2016 | Medium 4.6 | |
| CVE-2026-64922 | Microsoft SharePoint Enterprise Server 2016 | Medium 4.6 | |
| CVE-2026-61350 | Windows 10 Version 1607 | Medium 4.6 | |
| CVE-2026-62829 | Microsoft SharePoint Server 2019 | Medium 4.6 | |
| CVE-2026-58616 | Microsoft Edge (Chromium-based) | Medium 4.4 | |
| CVE-2026-62882 | Microsoft 365 Apps for Enterprise | Medium 4.3 | |
| CVE-2026-66798 | Microsoft Edge (Chromium-based) | Medium 4.3 |
References
Vendor advisory
- Microsoft SharePoint Server Remote Code Execution Vulnerability
- Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- Microsoft QUIC Remote Code Execution Vulnerability
- Windows DNS Server Remote Code Execution Vulnerability
- Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
- Windows iSCSI Target Service Remote Code Execution Vulnerability
- Microsoft Office SharePoint Spoofing Vulnerability
- Microsoft SharePoint Server Remote Code Execution Vulnerability
Other
CVE
- CVE-2026-65660 — cve.org
- CVE-2026-65660 — NVD
- CVE-2026-68820 — cve.org
- CVE-2026-68820 — NVD
- CVE-2026-62815 — cve.org
- CVE-2026-62815 — NVD
- CVE-2026-62878 — cve.org
- CVE-2026-62878 — NVD
- CVE-2026-62893 — cve.org
- CVE-2026-62893 — NVD
- CVE-2026-65791 — cve.org
- CVE-2026-65791 — NVD
- CVE-2026-70306 — cve.org
- CVE-2026-70306 — NVD
- CVE-2026-63514 — cve.org
- CVE-2026-63514 — NVD
- CVE-2026-64901 — cve.org
- CVE-2026-64901 — NVD
- CVE-2026-65658 — cve.org
- CVE-2026-65658 — NVD
- CVE-2026-65663 — cve.org
- CVE-2026-65663 — NVD
- CVE-2026-66805 — cve.org
- CVE-2026-66805 — NVD