Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
4 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability | Important | 24 Elevated | 5.5 | 0.005 | No | No | Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems |
| CVE-2026-63512 | Microsoft SharePoint Server Tampering Vulnerability | Important | 11 Elevated | 6.5 | 0.005 | No | No | Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition |
| CVE-2026-61928 | Windows Hello Tampering Vulnerability | Important | 9 Routine | 5.5 | 0.002 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +20 more |
| CVE-2026-62750 | Windows HTTP Protocol Stack Tampering Vulnerability | Important | 8 Routine | 6.5 | 0.006 | No | No | Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more |
The CSV is exactly the 4 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-72971 — Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Tampering
Recommended priority: Scheduled Maintenance
Why this score: Publicly disclosed before a patch shipped, and CVSS base score 5.5.
Exploitation status: Publicly Disclosed
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 5.5
FIRST EPSS: 0.005 (39.1st pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5121000
Affected product(s): Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems
CVE-2026-63512 — Microsoft SharePoint Server Tampering Vulnerability
Tampering
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.005 (43.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5002905, 5002906, 5002894, 5002896, 5002893
Affected product(s): Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition
CVE-2026-61928 — Windows Hello Tampering Vulnerability
Tampering
Recommended priority: Monitor
Why this score: CVSS base score 5.5, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 5.5
FIRST EPSS: 0.002 (11.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +20 more
CVE-2026-62750 — Windows HTTP Protocol Stack Tampering Vulnerability
Tampering
Recommended priority: Monitor
Why this score: CVSS base score 6.5, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 6.5
FIRST EPSS: 0.006 (45.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120238, 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000, 5120418, 5120386, 5120385
Affected product(s): Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022 (Server Core installation), +24 more