Microsoft Patch Tuesday

This month's Microsoft Security Update Guide release: severity and exploitation dashboards, a searchable CVE browser, and a downloadable brief.

Scope

Microsoft only, non-Microsoft, or both. Everything below follows the choice.

Why the two halves are ranked separately

This month's Microsoft Security Update Guide release. CVEs Microsoft republishes from third parties are excluded by default.

Release scope

Off by default: Microsoft's feed republishes CVEs it did not author (the Chromium engine behind Edge, Azure Linux package rebuilds). Rapid7 and Tenable exclude most of these from their own counts, so EVULNABLE does too unless you turn this on.

Methodology: why this count may differ from other vendors

Microsoft's feed for this release contains 2,003 total records: 599 are Microsoft-authored Patch Tuesday CVEs, and 1,404 are CVEs Microsoft republishes from third parties it ships or packages — the Chromium engine behind Microsoft Edge, and Azure Linux open-source package rebuilds, being the two largest categories. Rapid7 and Tenable report smaller headline counts for the same release because they apply their own (not fully published) methodology to exclude most of these. EVULNABLE's Microsoft-only figure is intended to land in the same ballpark, not to match exactly. All counts on this page reflect the scope selected above.

At a glance — Microsoft

3 CVE(s) are already being exploited in the wild, 5 are CISA KEV-listed, and 1 were publicly disclosed before this patch shipped — prioritize these regardless of severity.

Source: Microsoft Security Update Guide ↗

Patch First

Ranked by EVULNABLE Risk Score v1.1 — CVSS, FIRST EPSS, CISA KEV, confirmed active exploitation, pre-patch public disclosure, and Microsoft's Exploitability Index. Known active exploitation is floored regardless of CVSS alone.

Rank 1 CVE-2026-50522
CISA KEV

Microsoft SharePoint Remote Code Execution Vulnerability

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability.
CVSS v3.1 9.8EPSS 0.846 (99.69th pctl)MS EI Exploitation More Likely

Why it matters: Listed in the CISA KEV catalog, and an EPSS probability of 0.846.

Patch This Cycle
Rank 2 CVE-2026-58644
Actively ExploitedCISA KEV

Microsoft SharePoint Remote Code Execution Vulnerability

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability.
CVSS v3.1 9.8EPSS 0.159 (96.6th pctl)MS EI Exploitation Detected

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Patch This Cycle
Rank 3 CVE-2026-55040
CISA KEV

Microsoft SharePoint Server Security Feature Bypass Vulnerability

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability.
CVSS v3.1 9.1EPSS 0.397 (98.5th pctl)MS EI Exploitation More Likely

Why it matters: Listed in the CISA KEV catalog, and CVSS base score 9.1.

Patch This Cycle
Rank 4 CVE-2026-56155
Actively ExploitedCISA KEV

Active Directory Federation Services Elevation of Privilege Vulnerability

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability.
CVSS v3.1 7.8EPSS 0.003 (27.5th pctl)MS EI Exploitation Detected

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Patch This Cycle
Rank 5 CVE-2026-56164
Actively ExploitedCISA KEV

Microsoft SharePoint Server Elevation of Privilege Vulnerability

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability.
CVSS v3.1 5.3EPSS 0.266 (97.9th pctl)MS EI Exploitation Detected

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Patch This Cycle
Rank 6 CVE-2026-50661
Publicly Disclosed

Windows BitLocker Security Feature Bypass Vulnerability

EVULNABLE Risk · priority 27/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 6.1EPSS 0.005 (39.7th pctl)MS EI Exploitation Less Likely

Why it matters: Publicly disclosed before a patch shipped, and CVSS base score 6.1.

Scheduled Maintenance
Rank 7 CVE-2026-50518

Windows DHCP Server Remote Code Execution Vulnerability

EVULNABLE Risk · priority 19/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 9.8EPSS 0.010 (59.7th pctl)MS EI Exploitation More Likely

Why it matters: CVSS base score 9.8, and Microsoft Exploitability Index: Exploitation More Likely.

Scheduled Maintenance
Rank 8 CVE-2026-55010

Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability

EVULNABLE Risk · priority 19/100 Elevated Intelligence coverage 90/100 — no ransomware association data, no CISA KEV listing date
CVSS v3.1 9.8EPSS 0.010 (59.7th pctl)MS EI Exploitation More Likely

Why it matters: CVSS base score 9.8, and Microsoft Exploitability Index: Exploitation More Likely.

Scheduled Maintenance

Release Dashboard

CVEs by Severity (Microsoft)

  1. Critical 77
  2. Important 518
  3. Moderate 4

MSRC Severity · CVEs

Select a bar to filter the CVE browser below to that severity.

Top Affected Products

  1. Windows 10 Version 1809 617
  2. Windows Server 2019 615
  3. Windows 10 Version 21H2 355
  4. Windows Server 2022 329
  5. Microsoft Office 2019 152
  6. Microsoft 365 Apps for Enterprise 149
  7. Windows 11 Version 25H2 134
  8. Windows 11 Version 24H2 131
  9. Windows Server 2025 130
  10. Windows 10 Version 22H2 52

Product · CVEs

Hardware-architecture and Server Core installation variants of the same product are grouped into one bar. Distinct OS versions and Office LTSC years are kept separate, since they matter for what still needs to be patched.

Why do the Microsoft and EVULNABLE Risk severity views look so different?

Microsoft's severity rating (Critical / Important / Moderate / Low) is a technical-impact call: how bad this vulnerability could be if exploited, independent of whether anyone is actually exploiting it — which is why most CVEs in a typical release land in Critical or Important.

EVULNABLE Risk asks a different question: how urgently should this actually be remediated right now? It weights real-world exploitation signals — CISA KEV listing, confirmed active exploitation, FIRST EPSS, and pre-patch public disclosure — far more heavily than CVSS. Since most CVEs in any release are not yet known-exploited, most score Low or Informational under EVRS even when Microsoft calls them Critical. That is the point of a separate score, not a bug.

Any CVE that is CISA KEV-listed or confirmed actively exploited is floored regardless of the weighted total, so it can never get buried. A CVE that is KEV-listed and confirmed exploited and scores CVSS ≥ 9.0 — with a real urgency signal behind it — carries the Exigent flag and is escalated within Critical.

EVRS severity bands
BandScore
Immediate85-100
Urgent65-84
Elevated10-64
Routine4-9
Informational0-3

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.