Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
21 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-70306 | Microsoft Office SharePoint Spoofing Vulnerability | Important | 14 Elevated | 9.3 | 0.007 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-65767 | Microsoft Teams for Android Spoofing Vulnerability | Important | 13 Elevated | 8.8 | 0.005 | No | No | Microsoft Teams for Android |
| CVE-2026-56179 | Windows Network Address Translation (NAT) Spoofing Vulnerability | Moderate | 13 Elevated | 8.3 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-70332 | Microsoft Office SharePoint Spoofing Vulnerability | Critical | 12 Elevated | 9.6 | 0.006 | No | No | Microsoft SharePoint Online |
| CVE-2026-57105 | Microsoft Office SharePoint Spoofing Vulnerability | Important | 12 Elevated | 8.0 | 0.006 | No | No | Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-6726 | MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse | Important | 12 Elevated | 7.9 | 0.002 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
| CVE-2026-62914 | Microsoft Exchange Server Spoofing Vulnerability | Important | 12 Elevated | 7.3 | 0.003 | No | No | Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14 |
| CVE-2026-62869 | Azure Entra ID Spoofing Vulnerability | Critical | 11 Elevated | 8.8 | 0.008 | No | No | Microsoft Entra ID |
| CVE-2026-55013 | Windows Remote Help Defense Spoofing Vulnerability | Important | 11 Elevated | 7.1 | 0.002 | No | No | Windows Remote Help |
| CVE-2026-58639 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 11 Elevated | 6.5 | 0.008 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-62839 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 11 Elevated | 6.5 | 0.006 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-63516 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 11 Elevated | 6.5 | 0.013 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-62918 | Microsoft Teams Spoofing Vulnerability | Critical | 9 Routine | 7.5 | 0.005 | No | No | Microsoft Teams |
| CVE-2026-64900 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 9 Routine | 7.3 | 0.004 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-62829 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 9 Routine | 4.6 | 0.004 | No | No | Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-62917 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 9 Routine | 4.6 | 0.004 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-64897 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 9 Routine | 4.6 | 0.004 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-64922 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 9 Routine | 4.6 | 0.004 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-64902 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 6 Routine | 4.6 | 0.004 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-64916 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 6 Routine | 4.6 | 0.004 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-62882 | Microsoft Outlook Spoofing Vulnerability | Important | 6 Routine | 4.3 | 0.006 | No | No | Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more |
The CSV is exactly the 21 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-70306 — Microsoft Office SharePoint Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 9.3, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 9.3
FIRST EPSS: 0.007 (52.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002894, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-65767 — Microsoft Teams for Android Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 8.8
FIRST EPSS: 0.005 (37.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Teams for Android
CVE-2026-56179 — Windows Network Address Translation (NAT) Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.3, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 8.3
FIRST EPSS: 0.002 (14.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-70332 — Microsoft Office SharePoint Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 9.6, and an EPSS probability of 0.006.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 9.6
FIRST EPSS: 0.006 (47.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft SharePoint Online
CVE-2026-57105 — Microsoft Office SharePoint Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 8.0
FIRST EPSS: 0.006 (45.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-6726 — MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.9, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.9
FIRST EPSS: 0.002 (11.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5123303, 5120249, 5120233, 5120228, 5121003, 5120994, 5123607, 5123273, 5120240, 5121000, 5120418
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more
CVE-2026-62914 — Microsoft Exchange Server Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.3, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.3
FIRST EPSS: 0.003 (26.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5121576, 5121573, 5121574, 5121575
Affected product(s): Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14
CVE-2026-62869 — Azure Entra ID Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.8, and an EPSS probability of 0.008.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 8.8
FIRST EPSS: 0.008 (54.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Entra ID
CVE-2026-55013 — Windows Remote Help Defense Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.1, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.1
FIRST EPSS: 0.002 (13.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Windows Remote Help
CVE-2026-58639 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.008 (55.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-62839 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.006 (47.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-63516 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.013 (69.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-62918 — Microsoft Teams Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 7.5, and an EPSS probability of 0.005.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 7.5
FIRST EPSS: 0.005 (37.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
Affected product(s): Microsoft Teams
CVE-2026-64900 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 7.3, and an EPSS probability of 0.004.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 7.3
FIRST EPSS: 0.004 (37.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-62829 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 4.6, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 4.6
FIRST EPSS: 0.004 (28.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-62917 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 4.6, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 4.6
FIRST EPSS: 0.004 (36.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-64897 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 4.6, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 4.6
FIRST EPSS: 0.004 (34.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-64922 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 4.6, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 4.6
FIRST EPSS: 0.004 (34.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-64902 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 4.6, and an EPSS probability of 0.004.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 4.6
FIRST EPSS: 0.004 (34.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-64916 — Microsoft SharePoint Server Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 4.6, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 4.6
FIRST EPSS: 0.004 (34.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-62882 — Microsoft Outlook Spoofing Vulnerability
Spoofing
Recommended priority: Monitor
Why this score: CVSS base score 4.3, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 4.3
FIRST EPSS: 0.006 (47.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002755
Affected product(s): Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office LTSC 2021 for 64-bit editions, Microsoft Office LTSC 2021 for 32-bit editions, +4 more