Microsoft Patch Tuesday

This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.

Scope

Microsoft only, non-Microsoft, or both. Everything below follows the choice.

Why the two halves are ranked separately

This month's Microsoft Security Update Guide release. CVEs Microsoft republishes from third parties are excluded by default.

Release scope

Off by default: Microsoft's feed republishes CVEs it did not author (the Chromium engine behind Edge, Azure Linux package rebuilds). Rapid7 and Tenable exclude most of these from their own counts, so EVULNABLE does too unless you turn this on.

Methodology: why this count may differ from other vendors

Microsoft's feed for this release contains 1,640 total records: 448 are Microsoft-authored Patch Tuesday CVEs, and 1,192 are CVEs Microsoft republishes from third parties it ships or packages — the Chromium engine behind Microsoft Edge, and Azure Linux open-source package rebuilds, being the two largest categories. Rapid7 and Tenable report smaller headline counts for the same release because they apply their own (not fully published) methodology to exclude most of these. EVULNABLE's Microsoft-only figure is intended to land in the same ballpark, not to match exactly. All counts on this page reflect the scope selected above.

At a glance — Microsoft

1 CVE(s) are already being exploited in the wild, 1 are CISA KEV-listed, and 3 were publicly disclosed before this patch shipped — prioritize these regardless of severity.

Source: Microsoft Security Update Guide ↗

Patch First

Ranked by EVULNABLE Risk Score v1.1 — CVSS, FIRST EPSS, CISA KEV, confirmed active exploitation, pre-patch public disclosure, and Microsoft's Exploitability Index. Known active exploitation is floored regardless of CVSS alone.

Rank 1 CVE-2026-68820
Actively ExploitedCISA KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability.
CVSS v3.1 7.0EPSS 0.062 (93rd pctl)MS EI Exploitation Detected

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Patch This Cycle
Rank 2 CVE-2026-62832
Publicly Disclosed

Windows User Profile Service Elevation of Privilege Vulnerability

EVULNABLE Risk · priority 34/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 7.8EPSS 0.033 (87.7th pctl)MS EI Exploitation More Likely

Why it matters: Publicly disclosed before a patch shipped, and CVSS base score 7.8.

Scheduled Maintenance
Rank 3 CVE-2026-69414
Publicly Disclosed

Microsoft Defender Elevation of Privilege Vulnerability

EVULNABLE Risk · priority 33/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 7.8EPSS 0.006 (44.3rd pctl)MS EI Exploitation More Likely

Why it matters: Publicly disclosed before a patch shipped, and CVSS base score 7.8.

Scheduled Maintenance
Rank 4 CVE-2026-72971
Publicly Disclosed

Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability

EVULNABLE Risk · priority 24/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 5.5EPSS 0.005 (39.1st pctl)MS EI Exploitation Unlikely

Why it matters: Publicly disclosed before a patch shipped, and CVSS base score 5.5.

Scheduled Maintenance
Rank 5 CVE-2026-59124

Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability

EVULNABLE Risk · priority 19/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 9.8EPSS 0.017 (75.4th pctl)MS EI Exploitation More Likely

Why it matters: CVSS base score 9.8, and Microsoft Exploitability Index: Exploitation More Likely.

Scheduled Maintenance
Rank 6 CVE-2026-62893

Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

EVULNABLE Risk · priority 19/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 9.8EPSS 0.027 (85.1st pctl)MS EI Exploitation More Likely

Why it matters: CVSS base score 9.8, and Microsoft Exploitability Index: Exploitation More Likely.

Scheduled Maintenance
Rank 7 CVE-2026-59133

Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability

EVULNABLE Risk · priority 18/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 8.8EPSS 0.009 (58.6th pctl)MS EI Exploitation More Likely

Why it matters: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation More Likely.

Scheduled Maintenance
Rank 8 CVE-2026-62823

Windows DHCP Server Remote Code Execution Vulnerability

EVULNABLE Risk · priority 18/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 8.8EPSS 0.007 (49.3rd pctl)MS EI Exploitation More Likely

Why it matters: CVSS base score 8.8, and Microsoft Exploitability Index: Exploitation More Likely.

Scheduled Maintenance

Release Dashboard

CVEs by Severity (EVULNABLE Risk)

  1. Urgent 1
  2. Elevated 541
  3. Routine 666
  4. Informational 432

Severity · CVEs

Select a bar to filter the CVE browser below to that severity.

CVEs by Impact Type

  1. Elevation of Privilege 190
  2. Remote Code Execution 121
  3. Information Disclosure 95
  4. Spoofing 22
  5. Denial of Service 12
  6. Security Feature Bypass 12
  7. Tampering 5

Impact type · CVEs

1,183 CVE(s) have no impact classification stated by Microsoft and are excluded from this chart so they don't crowd out the categories that are known.

Top Affected Products

  1. azl3 kernel 6.6.150.1-1 on Azure Linux 3.0 419
  2. Windows Server 2022 390
  3. Windows Server 2019 366
  4. Microsoft Edge (Chromium-based) 360
  5. Windows 10 Version 1809 324
  6. azl3 kernel 6.6.143.1-1 on Azure Linux 3.0 177
  7. Microsoft 365 Apps for Enterprise 174
  8. Microsoft Office 2019 172
  9. Windows Server 2025 83
  10. Microsoft Office LTSC 2021 79

Product · CVEs

Hardware-architecture and Server Core installation variants of the same product are grouped into one bar. Distinct OS versions and Office LTSC years are kept separate, since they matter for what still needs to be patched.

Why do the Microsoft and EVULNABLE Risk severity views look so different?

Microsoft's severity rating (Critical / Important / Moderate / Low) is a technical-impact call: how bad this vulnerability could be if exploited, independent of whether anyone is actually exploiting it — which is why most CVEs in a typical release land in Critical or Important.

EVULNABLE Risk asks a different question: how urgently should this actually be remediated right now? It weights real-world exploitation signals — CISA KEV listing, confirmed active exploitation, FIRST EPSS, and pre-patch public disclosure — far more heavily than CVSS. Since most CVEs in any release are not yet known-exploited, most score Low or Informational under EVRS even when Microsoft calls them Critical. That is the point of a separate score, not a bug.

Any CVE that is CISA KEV-listed or confirmed actively exploited is floored regardless of the weighted total, so it can never get buried. A CVE that is KEV-listed and confirmed exploited and scores CVSS ≥ 9.0 — with a real urgency signal behind it — carries the Exigent flag and is escalated within Critical.

EVRS severity bands
BandScore
Immediate85-100
Urgent65-84
Elevated10-64
Routine4-9
Informational0-3

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.