Microsoft Patch Tuesday

This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.

Browse This Release's CVEs

Severity
Exploitation

6 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.

CVEs in this Patch Tuesday release matching the current filters, ranked by EVULNABLE Risk Score
CVE TitleMSRC severity EVRS CVSS EPSS KEV Actively Exploited Product(s)
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability Important 34 Elevated 7.8 0.033 No No Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-62888 Windows DWM Core Library Elevation of Privilege Vulnerability Important 17 Elevated 7.8 0.020 No No Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-62751 Windows Projected File System Elevation of Privilege Vulnerability Important 12 Elevated 7.8 0.003 No No Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability Important 11 Elevated 7.0 0.002 No No Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-62702 Windows Graphics Kernel Denial of Service Vulnerability Important 11 Elevated 6.8 0.009 No No Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-61355 Windows Sensor Data Service Elevation of Privilege Vulnerability Important 10 Elevated 7.8 0.003 No No Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
Download filtered CVEs (CSV) Patch Tuesday Brief (PDF)

The CSV is exactly the 6 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.

CVE detail

Expand any CVE for its description, EVRS score breakdown, and affected products.

CVE-2026-62832 — Windows User Profile Service Elevation of Privilege Vulnerability

Elevation of Privilege

EVULNABLE Risk · priority 34/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: Publicly disclosed before a patch shipped, and CVSS base score 7.8.

Exploitation status: Publicly Disclosed

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.033 (87.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more

CVE-2026-62888 — Windows DWM Core Library Elevation of Privilege Vulnerability

Elevation of Privilege

EVULNABLE Risk · priority 17/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation More Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.020 (78.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more

CVE-2026-62751 — Windows Projected File System Elevation of Privilege Vulnerability

Elevation of Privilege

EVULNABLE Risk · priority 12/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more

CVE-2026-59126 — Windows Event Logging Service Elevation of Privilege Vulnerability

Elevation of Privilege

EVULNABLE Risk · priority 11/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 7.0

FIRST EPSS: 0.002 (8.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more

CVE-2026-62702 — Windows Graphics Kernel Denial of Service Vulnerability

Denial of Service

EVULNABLE Risk · priority 11/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 6.8, and Microsoft Exploitability Index: Exploitation Less Likely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Less Likely

CVSS v3.1 base score: 6.8

FIRST EPSS: 0.009 (58.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more

CVE-2026-61355 — Windows Sensor Data Service Elevation of Privilege Vulnerability

Elevation of Privilege

EVULNABLE Risk · priority 10/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date

Recommended priority: Scheduled Maintenance

Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Unlikely.

Exploitation status: Neither

Microsoft Exploitability Index: Exploitation Unlikely

CVSS v3.1 base score: 7.8

FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA KEV: Not currently listed

KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000

Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.