Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
12 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59132 | Windows TCP/IP Denial of Service Vulnerability | Important | 16 Elevated | 7.5 | 0.017 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
| CVE-2026-62901 | .NET Denial of Service Vulnerability | Important | 12 Elevated | 7.5 | 0.011 | No | No | Microsoft Visual Studio 2026 version 18.8, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Linux, .NET 8.0 installed on Windows, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, +4 more |
| CVE-2026-65681 | Windows iSCSI Target Service Denial of Service Vulnerability | Important | 12 Elevated | 7.5 | 0.009 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +6 more |
| CVE-2026-62702 | Windows Graphics Kernel Denial of Service Vulnerability | Important | 11 Elevated | 6.8 | 0.009 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more |
| CVE-2026-59138 | Microsoft Remote Registry Service Denial of Service Vulnerability | Important | 11 Elevated | 6.5 | 0.010 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
| CVE-2026-61345 | Microsoft Remote Registry Service Denial of Service Vulnerability | Important | 11 Elevated | 6.5 | 0.010 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
| CVE-2026-62912 | Microsoft Exchange Server Denial of Service Vulnerability | Important | 11 Elevated | 6.5 | 0.013 | No | No | Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14 |
| CVE-2026-54113 | Remote Procedure Call Denial of Service Vulnerability | Important | 10 Elevated | 7.5 | 0.011 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +22 more |
| CVE-2026-55015 | Microsoft Remote Help Denial of Service Vulnerability | Important | 10 Elevated | 5.5 | 0.005 | No | No | Windows Remote Help |
| CVE-2026-70348 | Windows Management Services Denial of Service Vulnerability | Important | 10 Elevated | 5.5 | 0.004 | No | No | Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems |
| CVE-2026-65785 | Windows DHCP Client Denial of Service Vulnerability | Important | 8 Routine | 6.5 | 0.004 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-68819 | Windows Network File System Denial of Service Vulnerability | Important | 8 Routine | 5.9 | 0.007 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +10 more |
The CSV is exactly the 12 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-59132 — Windows TCP/IP Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.5, and Microsoft Exploitability Index: Exploitation More Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.5
FIRST EPSS: 0.017 (75.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-62901 — .NET Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.5
FIRST EPSS: 0.011 (62.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5122106, 5122104, 5122105
Affected product(s): Microsoft Visual Studio 2026 version 18.8, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Linux, .NET 8.0 installed on Windows, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, +4 more
CVE-2026-65681 — Windows iSCSI Target Service Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.5
FIRST EPSS: 0.009 (56.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +6 more
CVE-2026-62702 — Windows Graphics Kernel Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.8
FIRST EPSS: 0.009 (58.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-59138 — Microsoft Remote Registry Service Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.010 (61.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-61345 — Microsoft Remote Registry Service Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.010 (61.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-62912 — Microsoft Exchange Server Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.013 (68.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5121573, 5121574, 5121576, 5121575
Affected product(s): Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14
CVE-2026-54113 — Remote Procedure Call Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.5, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 7.5
FIRST EPSS: 0.011 (64.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +22 more
CVE-2026-55015 — Microsoft Remote Help Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 5.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 5.5
FIRST EPSS: 0.005 (40.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Windows Remote Help
CVE-2026-70348 — Windows Management Services Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 5.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 5.5
FIRST EPSS: 0.004 (35.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5121003, 5120994, 5121000
Affected product(s): Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems
CVE-2026-65785 — Windows DHCP Client Denial of Service Vulnerability
Denial of Service
Recommended priority: Monitor
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.004 (30.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-68819 — Windows Network File System Denial of Service Vulnerability
Denial of Service
Recommended priority: Monitor
Why this score: CVSS base score 5.9, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 5.9
FIRST EPSS: 0.007 (50.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +10 more