Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
7 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62832 | Windows User Profile Service Elevation of Privilege Vulnerability | Important | 34 Elevated | 7.8 | 0.033 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more |
| CVE-2026-66804 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | Important | 18 Elevated | 7.8 | 0.053 | No | No | Windows 10 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for 32-bit Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +3 more |
| CVE-2026-62888 | Windows DWM Core Library Elevation of Privilege Vulnerability | Important | 17 Elevated | 7.8 | 0.020 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more |
| CVE-2026-62751 | Windows Projected File System Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more |
| CVE-2026-59126 | Windows Event Logging Service Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more |
| CVE-2026-62702 | Windows Graphics Kernel Denial of Service Vulnerability | Important | 11 Elevated | 6.8 | 0.009 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more |
| CVE-2026-61355 | Windows Sensor Data Service Elevation of Privilege Vulnerability | Important | 10 Elevated | 7.8 | 0.003 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more |
The CSV is exactly the 7 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-62832 — Windows User Profile Service Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: Publicly disclosed before a patch shipped, and CVSS base score 7.8.
Exploitation status: Publicly Disclosed
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.033 (87.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-66804 — Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.053 (92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120249, 5121003, 5120994, 5121000
Affected product(s): Windows 10 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for 32-bit Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +3 more
CVE-2026-62888 — Windows DWM Core Library Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.020 (78.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-62751 — Windows Projected File System Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-59126 — Windows Event Logging Service Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (8.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-62702 — Windows Graphics Kernel Denial of Service Vulnerability
Denial of Service
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 6.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 6.8
FIRST EPSS: 0.009 (58.6th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more
CVE-2026-61355 — Windows Sensor Data Service Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120249, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems, Windows 10 Version 22H2 for x64-based Systems, +12 more