Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
93 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69558 | Microsoft Partner Center Information Disclosure Vulnerability | Critical | 17 Elevated | 8.6 | 0.005 | No | No | Microsoft Partner Center |
| CVE-2026-56161 | Azure Logic Apps Information Disclosure Vulnerability | Critical | 12 Elevated | 9.6 | 0.005 | No | No | Azure Logic Apps |
| CVE-2026-24301 | Microsoft Copilot Information Disclosure Vulnerability | Critical | 12 Elevated | 8.8 | 0.022 | No | No | Copilot Web |
| CVE-2026-70313 | Microsoft PowerPoint Remote Code Execution Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +5 more |
| CVE-2026-62898 | Microsoft QUIC Information Disclosure Vulnerability | Important | 12 Elevated | 7.5 | 0.011 | No | No | .NET 10.0 installed on Windows, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8, .NET 9.0 installed on Windows, .NET 8.0 installed on Windows |
| CVE-2026-58612 | PowerShell Information Disclosure Vulnerability | Important | 12 Elevated | 7.4 | 0.008 | No | No | PowerShell 7.5, PowerShell 7.4, PowerShell 7.6 |
| CVE-2026-66800 | Azure Data Factory Information Disclosure Vulnerability | Critical | 11 Elevated | 8.6 | 0.005 | No | No | Azure Data Factory |
| CVE-2026-69519 | Azure Stack HCI Information Disclosure Vulnerability | Critical | 11 Elevated | 8.6 | 0.006 | No | No | Azure Stack HCI |
| CVE-2026-40375 | Microsoft Dynamics Business Central Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.008 | No | No | Microsoft Dynamics 365 Business Central 2024 Release Wave 2, Microsoft Dynamics 365 Business Central Release Wave 1 2025, Microsoft Dynamics 365 Business Central 2026 Release Wave 1, Microsoft Dynamics 365 Business Central Release Wave 2 2025 |
| CVE-2026-47285 | Visual Studio Code Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.009 | No | No | Visual Studio Code |
| CVE-2026-61918 | Windows Remote Desktop Client Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.009 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
| CVE-2026-61921 | Windows Remote Desktop Client Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.008 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
| CVE-2026-61924 | Windows Remote Desktop Client Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.008 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
| CVE-2026-62742 | Windows DHCP Server Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.005 | No | No | Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more |
| CVE-2026-62745 | Windows DHCP Server Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.004 | No | No | Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more |
| CVE-2026-62814 | Windows DHCP Server Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.005 | No | No | Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more |
| CVE-2026-62837 | Microsoft SharePoint Server Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.009 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-62902 | .NET Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.008 | No | No | .NET 8.0 installed on Windows, .NET 9.0 installed on Windows, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8 |
| CVE-2026-65769 | Microsoft Teams iOS Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.007 | No | No | Microsoft Teams for iOS |
| CVE-2026-65806 | Azure CycleCloud Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.006 | No | No | Azure CycleCloud 8.9.2 |
| CVE-2026-66301 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.007 | No | No | Microsoft Dynamics 365 (on-premises) version 9.1 |
| CVE-2026-69550 | Windows App for Mac Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.007 | No | No | Windows App for Mac |
| CVE-2026-70105 | Microsoft Word Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.005 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more |
| CVE-2026-70327 | Microsoft Excel Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.009 | No | No | Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more |
| CVE-2026-70328 | Microsoft Excel Information Disclosure Vulnerability | Important | 11 Elevated | 6.5 | 0.009 | No | No | Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more |
The CSV is exactly the 93 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-69558 — Microsoft Partner Center Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.6, and Microsoft Exploitability Index: Exploitation More Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 8.6
FIRST EPSS: 0.005 (43.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Partner Center
CVE-2026-56161 — Azure Logic Apps Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 9.6, and an EPSS probability of 0.005.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 9.6
FIRST EPSS: 0.005 (38.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Azure Logic Apps
CVE-2026-24301 — Microsoft Copilot Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.8, and an EPSS probability of 0.022.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 8.8
FIRST EPSS: 0.022 (81.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Copilot Web
CVE-2026-70313 — Microsoft PowerPoint Remote Code Execution Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (25.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Office 365 for Mac, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, +5 more
CVE-2026-62898 — Microsoft QUIC Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.5
FIRST EPSS: 0.011 (63.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5122106, 5122105, 5122104
Affected product(s): .NET 10.0 installed on Windows, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8, .NET 9.0 installed on Windows, .NET 8.0 installed on Windows
CVE-2026-58612 — PowerShell Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.4, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.4
FIRST EPSS: 0.008 (54.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): PowerShell 7.5, PowerShell 7.4, PowerShell 7.6
CVE-2026-66800 — Azure Data Factory Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.6, and an EPSS probability of 0.005.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 8.6
FIRST EPSS: 0.005 (43.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Azure Data Factory
CVE-2026-69519 — Azure Stack HCI Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.6, and an EPSS probability of 0.006.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 8.6
FIRST EPSS: 0.006 (44.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Azure Stack HCI
CVE-2026-40375 — Microsoft Dynamics Business Central Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.008 (53.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5100263, 5100266, 5100265
Affected product(s): Microsoft Dynamics 365 Business Central 2024 Release Wave 2, Microsoft Dynamics 365 Business Central Release Wave 1 2025, Microsoft Dynamics 365 Business Central 2026 Release Wave 1, Microsoft Dynamics 365 Business Central Release Wave 2 2025
CVE-2026-47285 — Visual Studio Code Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.009 (56.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Visual Studio Code
CVE-2026-61918 — Windows Remote Desktop Client Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.009 (56.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-61921 — Windows Remote Desktop Client Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.008 (55.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-61924 — Windows Remote Desktop Client Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.008 (55.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-62742 — Windows DHCP Server Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.005 (39.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385
Affected product(s): Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more
CVE-2026-62745 — Windows DHCP Server Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.004 (29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385
Affected product(s): Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more
CVE-2026-62814 — Windows DHCP Server Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.005 (43.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385
Affected product(s): Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more
CVE-2026-62837 — Microsoft SharePoint Server Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.009 (56.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-62902 — .NET Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.008 (53.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5122104, 5122105
Affected product(s): .NET 8.0 installed on Windows, .NET 9.0 installed on Windows, Microsoft Visual Studio 2022 version 17.14, Microsoft Visual Studio 2026 version 18.8
CVE-2026-65769 — Microsoft Teams iOS Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.007 (49.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Teams for iOS
CVE-2026-65806 — Azure CycleCloud Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.006 (45.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Azure CycleCloud 8.9.2
CVE-2026-66301 — Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.007 (50.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Dynamics 365 (on-premises) version 9.1
CVE-2026-69550 — Windows App for Mac Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.007 (48.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Windows App for Mac
CVE-2026-70105 — Microsoft Word Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.005 (43.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002901
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021 for 64-bit editions, +7 more
CVE-2026-70327 — Microsoft Excel Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.009 (55.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002884, 5002903
Affected product(s): Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more
CVE-2026-70328 — Microsoft Excel Information Disclosure Vulnerability
Information Disclosure
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.009 (55.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002884, 5002903
Affected product(s): Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more