Microsoft Patch Tuesday
This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.
Browse This Release's CVEs
38 of 448 CVEs match the current filters, sorted by EVULNABLE Risk.
| CVE | Title | MSRC severity | EVRS | CVSS | EPSS | KEV | Actively Exploited | Product(s) |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66804 | Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | Important | 18 Elevated | 7.8 | 0.053 | No | No | Windows 10 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for 32-bit Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +3 more |
| CVE-2026-62688 | Windows MIDI Service Module Elevation of Privileges Vulnerability | Important | 17 Elevated | 7.8 | 0.004 | No | No | Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems |
| CVE-2026-62737 | Windows Kernel Elevation of Privilege Vulnerability | Important | 17 Elevated | 7.8 | 0.028 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-61929 | Windows Kernel Elevation of Privilege Vulnerability | Important | 16 Elevated | 7.0 | 0.017 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more |
| CVE-2026-62766 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 16 Elevated | 7.0 | 0.015 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-62788 | Windows Kernel Elevation of Privilege Vulnerability | Important | 16 Elevated | 7.0 | 0.003 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more |
| CVE-2026-65788 | Desktop Window Manager Elevation of Privilege Vulnerability | Important | 16 Elevated | 7.0 | 0.017 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more |
| CVE-2026-56179 | Windows Network Address Translation (NAT) Spoofing Vulnerability | Moderate | 13 Elevated | 8.3 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-62815 | Microsoft QUIC Remote Code Execution Vulnerability | Critical | 12 Elevated | 9.8 | 0.010 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more |
| CVE-2026-61357 | Application Information Services Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-61359 | Windows Storage Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more |
| CVE-2026-61934 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more |
| CVE-2026-62695 | Windows Storage Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more |
| CVE-2026-62722 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-62811 | Windows HTTP.sys Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more |
| CVE-2026-65672 | Remote Access API Elevation of Privilege Vulnerability | Important | 12 Elevated | 7.8 | 0.003 | No | No | Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more |
| CVE-2026-61927 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-61938 | Windows Installer Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-62705 | Microsoft Brokering File System Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems |
| CVE-2026-62749 | Windows Kernel Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-62780 | Windows Kernel Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more |
| CVE-2026-65776 | Windows Win32k Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
| CVE-2026-65783 | Windows Autopilot Elevation of Privilege Vulnerability | Important | 11 Elevated | 7.0 | 0.002 | No | No | Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems |
| CVE-2026-62736 | Windows DHCP Client Elevation of Privilege Vulnerability | Important | 10 Elevated | 7.8 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more |
| CVE-2026-62779 | Windows Schannel Elevation of Privilege Vulnerability | Important | 10 Elevated | 7.8 | 0.002 | No | No | Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more |
The CSV is exactly the 38 CVE(s) matching the filters above. The PDF is the full leadership brief — at-a-glance summary, Patch First spotlight, top affected products, and the complete per-CVE inventory — not filtered to what is shown here.
CVE detail
Expand any CVE for its description, EVRS score breakdown, and affected products.
CVE-2026-66804 — Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.053 (92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120249, 5121003, 5120994, 5121000
Affected product(s): Windows 10 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for 32-bit Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +3 more
CVE-2026-62688 — Windows MIDI Service Module Elevation of Privileges Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.004 (29th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5121003, 5120994, 5121000
Affected product(s): Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems
CVE-2026-62737 — Windows Kernel Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation More Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.028 (85.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-61929 — Windows Kernel Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: Microsoft Exploitability Index: Exploitation More Likely, and CVSS base score 7.0.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.017 (75.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more
CVE-2026-62766 — Windows Kerberos Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: Microsoft Exploitability Index: Exploitation More Likely, and CVSS base score 7.0.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.015 (72.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-62788 — Windows Kernel Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: Microsoft Exploitability Index: Exploitation More Likely, and CVSS base score 7.0.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.003 (25.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more
CVE-2026-65788 — Desktop Window Manager Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: Microsoft Exploitability Index: Exploitation More Likely, and CVSS base score 7.0.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation More Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.017 (75.3rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more
CVE-2026-56179 — Windows Network Address Translation (NAT) Spoofing Vulnerability
Spoofing
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 8.3, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 8.3
FIRST EPSS: 0.002 (14.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-62815 — Microsoft QUIC Remote Code Execution Vulnerability
Remote Code Execution
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 9.8, and an EPSS probability of 0.010.
Exploitation status: Neither
Microsoft Exploitability Index: N/A
CVSS v3.1 base score: 9.8
FIRST EPSS: 0.010 (59.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more
CVE-2026-61357 — Application Information Services Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-61359 — Windows Storage Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more
CVE-2026-61934 — Windows Bind Filter Driver Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more
CVE-2026-62695 — Windows Storage Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more
CVE-2026-62722 — Microsoft Brokering File System Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (23.4th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-62811 — Windows HTTP.sys Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (26th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more
CVE-2026-65672 — Remote Access API Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.003 (17.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120242, 5120229, 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, +6 more
CVE-2026-61927 — Windows Bind Filter Driver Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (8.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-61938 — Windows Installer Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (15.7th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-62705 — Microsoft Brokering File System Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (8.5th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5121003, 5120994, 5121000
Affected product(s): Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems
CVE-2026-62749 — Windows Kernel Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (9.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-62780 — Windows Kernel Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (10.2nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more
CVE-2026-65776 — Windows Win32k Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (13th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more
CVE-2026-65783 — Windows Autopilot Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.0, and Microsoft Exploitability Index: Exploitation Less Likely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Less Likely
CVSS v3.1 base score: 7.0
FIRST EPSS: 0.002 (9.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5121003, 5120994
Affected product(s): Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems
CVE-2026-62736 — Windows DHCP Client Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.002 (14.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5120240, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, +4 more
CVE-2026-62779 — Windows Schannel Elevation of Privilege Vulnerability
Elevation of Privilege
Recommended priority: Scheduled Maintenance
Why this score: CVSS base score 7.8, and Microsoft Exploitability Index: Exploitation Unlikely.
Exploitation status: Neither
Microsoft Exploitability Index: Exploitation Unlikely
CVSS v3.1 base score: 7.8
FIRST EPSS: 0.002 (14.9th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs
CISA KEV: Not currently listed
KB article(s): 5120233, 5120228, 5121003, 5120994, 5121000
Affected product(s): Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, +2 more