Microsoft Patch Tuesday

This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.

Browse This Release's CVEs

Severity
Exploitation

11 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.

CVEs in this Patch Tuesday release matching the current filters, ranked by EVULNABLE Risk Score
CVE TitleMSRC severity EVRS CVSS EPSS KEV Actively Exploited Product(s)
CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability Important 17 Elevated 7.8 0.003 No No Visual Studio Code
CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability Important 17 Elevated 7.8 0.003 No No Visual Studio Code
CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability Important 13 Elevated 8.2 0.004 No No Visual Studio Code
CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability Important 12 Elevated 7.8 0.004 No No Python extension for Visual Studio Code
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability Important 12 Elevated 7.8 0.003 No No PowerShell 7.4, PowerShell 7.5, PowerShell 7.6
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability Important 11 Elevated 7.1 0.005 No No Microsoft Visual Studio Code CoPilot Chat Extension
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability Important 11 Elevated 6.5 0.005 No No Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14
CVE-2026-62899 .NET Security Feature Bypass Vulnerability Important 10 Elevated 5.9 0.007 No No .NET 10.0 installed on Mac OS, .NET 10.0 installed on Linux, .NET 8.0 installed on Windows, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 9.0 installed on Linux, +4 more
CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability Important 7 Routine 5.5 0.003 No No Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +16 more
CVE-2026-62757 Windows Schannel Security Feature Bypass Vulnerability Important 7 Routine 5.3 0.003 No No Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability Important 7 Routine 5.3 0.003 No No Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more
Download filtered CVEs (CSV) Patch Tuesday Brief (PDF)

The CSV is exactly the 11 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.

CVE detail

Expand any CVE for its description, EVRS score breakdown, and affected products.

CVE-2026-58650 — Visual Studio Code Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 17/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (21.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Visual Studio Code

CVE-2026-69278 — Visual Studio Code Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 17/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (21.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Visual Studio Code

CVE-2026-69306 — Visual Studio Code Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 13/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 8.2, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 8.2

FIRST EPSS: 0.004 (34.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Visual Studio Code

CVE-2026-54981 — Visual Studio Code Python Extension Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.004 (32.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Python extension for Visual Studio Code

CVE-2026-70338 — Microsoft PowerShell Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): PowerShell 7.4, PowerShell 7.5, PowerShell 7.6

CVE-2026-65675 — CoPilot Chat Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 11/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.1, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.1

FIRST EPSS: 0.005 (40.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

Affected product(s): Microsoft Visual Studio Code CoPilot Chat Extension

CVE-2026-62915 — Microsoft Exchange Server Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 11/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 6.5

FIRST EPSS: 0.005 (39.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5121576, 5121573, 5121574, 5121575

Affected product(s): Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14

CVE-2026-62899 — .NET Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 10/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 5.9, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 5.9

FIRST EPSS: 0.007 (50.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5122106, 5122104, 5122105

Affected product(s): .NET 10.0 installed on Mac OS, .NET 10.0 installed on Linux, .NET 8.0 installed on Windows, .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 9.0 installed on Linux, +4 more

CVE-2026-61936 — Windows Defender Firewall Service Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 7/100 Routine Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Monitor

Why this score: CVSS base score 5.5, and Microsoft Exploitability Index: Exploitation Unlikely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Unlikely

CVSS v3.1 base score: 5.5

FIRST EPSS: 0.003 (20.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +16 more

CVE-2026-62757 — Windows Schannel Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 7/100 Routine Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Monitor

Why this score: CVSS base score 5.3, and Microsoft Exploitability Index: Exploitation Unlikely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Unlikely

CVSS v3.1 base score: 5.3

FIRST EPSS: 0.003 (16.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385

Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more

CVE-2026-65777 — Active Directory Security Feature Bypass Vulnerability

Security Feature Bypass

EVULNABLE Risk · priority 7/100 Routine Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Monitor

Why this score: CVSS base score 5.3, and Microsoft Exploitability Index: Exploitation Unlikely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Unlikely

CVSS v3.1 base score: 5.3

FIRST EPSS: 0.003 (20.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120242, 5120229, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.