Microsoft Patch Tuesday

This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.

Browse This Release's CVEs

Severity
Exploitation

118 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.

CVEs in this Patch Tuesday release matching the current filters, ranked by EVULNABLE Risk Score
CVE TitleMSRC severity EVRS CVSS EPSS KEV Actively Exploited Product(s)
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability Important 19 Elevated 9.8 0.017 No No Microsoft HPC Pack 2019
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Critical 19 Elevated 9.8 0.027 No No Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability Critical 18 Elevated 8.8 0.007 No No Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more
CVE-2026-65665 Microsoft SharePoint Server Remote Code Execution Vulnerability Critical 18 Elevated 8.8 0.028 No No Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 17 Elevated 8.1 0.029 No No Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability Critical 15 Elevated 10.0 0.016 No No Microsoft Entra ID
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability Critical 15 Elevated 9.8 0.013 No No Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more
CVE-2026-64901 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 14 Elevated 8.8 0.019 No No Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability Critical 13 Elevated 10.0 0.006 No No Azure Managed Instance for Apache Cassandra
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability Critical 13 Elevated 9.9 0.011 No No Azure Service Bus
CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.007 No No Visual Studio Code
CVE-2026-62790 Windows SMBv3 Server Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.007 No No Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-62816 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Critical 13 Elevated 8.8 0.004 No No Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-62817 Windows DNS Server Remote Code Execution Vulnerability Critical 13 Elevated 8.8 0.007 No No Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025
CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Critical 13 Elevated 8.8 0.010 No No Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +10 more
CVE-2026-62822 Windows GDI+ Remote Code Execution Vulnerability Critical 13 Elevated 8.8 0.006 No No Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-62824 Remote Desktop Client Remote Code Execution Vulnerability Critical 13 Elevated 8.8 0.006 No No Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), +2 more
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.007 No No Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14
CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.015 No No Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-65658 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.014 No No Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.008 No No Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-65663 Microsoft SharePoint Server Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.014 No No Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.006 No No Microsoft Teams for Android
CVE-2026-65807 Microsoft Excel Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.004 No No Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more
CVE-2026-65811 Power BI Remote Code Execution Vulnerability Important 13 Elevated 8.8 0.005 No No Power BI Report Server
Download filtered CVEs (CSV) Patch Tuesday Brief (PDF)

The CSV is exactly the 118 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.

CVE detail

Expand any CVE for its description, EVRS score breakdown, and affected products.

CVE-2026-59124 — Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 19/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 9.8, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 9.8

FIRST EPSS: 0.017 (75.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft HPC Pack 2019

CVE-2026-62893 — Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 19/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 9.8, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 9.8

FIRST EPSS: 0.027 (85.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385

Affected product(s): Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more

CVE-2026-62823 — Windows DHCP Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 18/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.007 (49.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385

Affected product(s): Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more

CVE-2026-65665 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 18/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.028 (85.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002894, 5002896, 5002893

Affected product(s): Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

CVE-2026-63520 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 17/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.1, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 8.1

FIRST EPSS: 0.029 (86th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893

Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

CVE-2026-69836 — Microsoft Entra ID Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 15/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 10.0, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 10.0

FIRST EPSS: 0.016 (73.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Entra ID

CVE-2026-62878 — Windows DNS Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 15/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 9.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 9.8

FIRST EPSS: 0.013 (67.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385

Affected product(s): Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025, +6 more

CVE-2026-64901 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 14/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.019 (78.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893

Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

CVE-2026-65770 — Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 80/100 — no Microsoft Exploitability Index, no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 10.0, and an EPSS probability of 0.006.

Exploitation status: Neither

Microsoft Exploitability Index: N/A

CVSS v3.1 base score: 10.0

FIRST EPSS: 0.006 (44.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Azure Managed Instance for Apache Cassandra

CVE-2026-50515 — Azure Service Bus Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 80/100 — no Microsoft Exploitability Index, no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 9.9, and an EPSS probability of 0.011.

Exploitation status: Neither

Microsoft Exploitability Index: N/A

CVSS v3.1 base score: 9.9

FIRST EPSS: 0.011 (63.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Azure Service Bus

CVE-2026-59113 — Visual Studio Code Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.007 (50.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Visual Studio Code

CVE-2026-62790 — Windows SMBv3 Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.007 (49.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385

Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more

CVE-2026-62816 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.004 (32.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385

Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more

CVE-2026-62817 — Windows DNS Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.007 (49.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228

Affected product(s): Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows Server 2025

CVE-2026-62818 — Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.010 (59.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120233, 5120228, 5120418, 5120386, 5120385

Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +10 more

CVE-2026-62822 — Windows GDI+ Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.006 (48th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385

Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more

CVE-2026-62824 — Remote Desktop Client Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.006 (47.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120418, 5120386, 5120385

Affected product(s): Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), +2 more

CVE-2026-62913 — Microsoft Exchange Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.007 (48.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5121576, 5121573, 5121574, 5121575

Affected product(s): Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14

CVE-2026-63514 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.015 (72.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893

Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

CVE-2026-65658 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.014 (70.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893

Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

CVE-2026-65660 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.008 (54.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893

Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

CVE-2026-65663 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.014 (70.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893

Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition

CVE-2026-65768 — Microsoft Teams Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.006 (47.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Teams for Android

CVE-2026-65807 — Microsoft Excel Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.004 (36.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5002884, 5002903

Affected product(s): Microsoft Office 365 for Mac, Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, +8 more

CVE-2026-65811 — Power BI Remote Code Execution Vulnerability

Remote Code Execution

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.8

FIRST EPSS: 0.005 (42.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Power BI Report Server

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.