Skip to main content
EVULNABLE Home

Patch advisories

Microsoft's release and everyone else's — ranked by the same EVRS scale as the priority feed.

Microsoft — this release

1 advisory. Data checked 07 Sep 11:30 UTC.

#1
Patch TuesdayActively Exploited
75

Microsoft release dashboard

This month's Microsoft release, by risk, by impact and by the products it touches.

CVEs by impact type

  • Elevation of Privilege 190
  • Remote Code Execution 116
  • Information Disclosure 93
  • Spoofing 21
  • Denial of Service 12
  • Security Feature Bypass 11
  • Tampering 4

1 CVE in this release carry no impact classification from Microsoft. They are counted here rather than charted as "Not stated", which would be the largest bar and would say nothing about impact.

Top affected products

  • Windows Server 2022 390
  • Windows Server 2019 366
  • Windows 10 Version 1809 324
  • Microsoft 365 Apps for Enterprise 174
  • Microsoft Office 2019 172
  • Windows Server 2025 83
  • Microsoft Office LTSC 2021 79
  • Windows 11 Version 25H2 76
  • Microsoft Office LTSC for Mac 2021 62
  • Windows 11 Version 24H2 56

Hardware-architecture and Server Core variants of the same product are grouped into one bar. Distinct OS versions and Office LTSC years are kept separate, since they matter for what still needs patching.

Linux distribution advisories

25 of 684, from Debian, Red Hat, Ubuntu.

AdvisorySourceSeverityCVEsDate
CVE-2026-64849 ↗
mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Red Hat Important 1 2026-08-17
CVE-2026-66804 ↗
console: Authenticated SSRF via user-controlled towerHost in /ansibletower handler
Red Hat Important 1 2026-08-13
CVE-2026-18963 ↗
keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass
Red Hat Critical 1 2026-08-17
USN-8728-1 ↗
Linux kernel (GCP) vulnerabilities
Ubuntu Not stated 1417 2026-09-07
CVE-2024-58376 ↗
renovate: Renovate 37.158.0 before 37.199.0 Command Injection via helmv3
Red Hat Important 1 2026-08-19
CVE-2026-66805 ↗
console: Stored DOM XSS via unescaped pod logs in document.write
Red Hat Important 1 2026-08-10
CVE-2026-71364 ↗
awx: project archive extraction allows path traversal file writes
Red Hat Important 1 2026-08-24
USN-8715-1 ↗
Linux kernel (Oracle) vulnerabilities
Ubuntu Not stated 37 2026-09-02
CVE-2026-62901 ↗
.NET: .NET Denial of Service Vulnerability
Red Hat Important 1 2026-08-11
CVE-2026-71471 ↗
acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image
Red Hat Important 1 2026-08-12
USN-8661-4 ↗
Linux kernel vulnerabilities
Ubuntu Not stated 21 2026-09-02
CVE-2026-73623 ↗
gitpython: GitPython: Remote Code Execution via malicious Git template
Red Hat Important 1 2026-08-13
CVE-2026-63639 ↗
valkey: Valkey: Remote code execution via use-after-free in stream deserialization
Red Hat Important 1 2026-08-18
CVE-2026-5917 ↗
libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend
Red Hat Important 1 2026-08-11
CVE-2026-84218 ↗
org.jolokia/jolokia-core: Incomplete JNDI Denylist in Jolokia JSR-160 Proxy (Bypass of CVE-2018-1000130 Fix)
Red Hat Important 1 2026-09-01
CVE-2026-68763 ↗
org.apache.tomcat/tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak
Red Hat Important 1 2026-08-25
CVE-2026-76036 ↗
chromium-browser: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page
Red Hat Important 1 2026-08-18
CVE-2026-48752 ↗
incus: Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Red Hat Critical 1 2026-08-21
CVE-2026-48749 ↗
incus: Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
Red Hat Critical 1 2026-08-21
CVE-2026-71513 ↗
nltk: NLTK: Remote Code Execution via AllowlistUnpickler dotted-name bypass
Red Hat Important 1 2026-08-22
CVE-2026-48750 ↗
incus: Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
Red Hat Critical 1 2026-08-21
CVE-2026-65927 ↗
tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing
Red Hat Important 1 2026-08-25
USN-8727-1 ↗
Linux kernel (OEM) vulnerabilities
Ubuntu Not stated 547 2026-09-07
USN-8726-1 ↗
Linux kernel vulnerabilities
Ubuntu Not stated 551 2026-09-07
CVE-2026-66793 ↗
governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke
Red Hat Important 1 2026-08-18

Vendor bulletins

25 of 91, from Adobe, Apple, Chrome, Cisco, Ivanti, Oracle.

BulletinSourceTypeCVEsPublished
Chrome 152.0.7977.82 ↗
Stable Channel Update for Desktop — 152.0.7977.82
Chrome High CVE-2026-85042, CVE-2026-85043, CVE-2026-85044, CVE-2026-85045, CVE-2026-85046, CVE-2026-85047, CVE-2026-85048, CVE-2026-85049, CVE-2026-85050, CVE-2026-85051, CVE-2026-85052, CVE-2026-85053 2026-09-03
cisco-sa-hardening-iosxr-qg64NcM ↗
Cisco IOS XR Software Security Hardening Release: September 2026
Cisco Critical CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277, CVE-2026-20278, CVE-2026-20279, CVE-2026-20280 2026-09-02
cisco-sa-phone-dos-txMYNRzv ↗
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
Cisco High CVE-2026-20281 2026-09-02
cisco-sa-esa-smime-disc-dzw4rEdY ↗
Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities
Cisco Medium CVE-2026-20354, CVE-2026-20355 2026-09-02
cisco-sa-n9k-s1-rce-EH8dEtr ↗
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Cisco Critical CVE-2026-20212 2026-09-02
Chrome 152.0.7977.75 ↗
Stable Channel Update for Desktop — 152.0.7977.75
Chrome Critical CVE-2026-84323, CVE-2026-84324, CVE-2026-84325, CVE-2026-84326, CVE-2026-84327, CVE-2026-84328, CVE-2026-84329, CVE-2026-84330, CVE-2026-84331, CVE-2026-84332, CVE-2026-84333, CVE-2026-84334, CVE-2026-84335, CVE-2026-84347, CVE-2026-84348, CVE-2026-84349, CVE-2026-84350, CVE-2026-84351, CVE-2026-84352, CVE-2026-84353, CVE-2026-84354, CVE-2026-84355, CVE-2026-84356, CVE-2026-84357, CVE-2026-84358, CVE-2026-84359 2026-09-01
cisco-sa-notice-f2SiMFxl ↗
Cisco Advance Notification for Publication of September 2, 2026, Security Advisories
Cisco Informational Not listed 2026-08-26
APSB26-110 ↗
Security update available for Content Credentials SDK
Adobe Bulletin Not listed 2026-08-25
APSB26-115 ↗
Security update available for Adobe Substance 3D Designer
Adobe Bulletin Not listed 2026-08-25
APSB26-121 ↗
Security update available for Adobe Substance 3D Sampler
Adobe Bulletin Not listed 2026-08-25
APSB26-124 ↗
Security update available for Adobe Illustrator
Adobe Bulletin Not listed 2026-08-25
APSB26-125 ↗
Security update available for Adobe XD
Adobe Bulletin Not listed 2026-08-25
APSB26-129 ↗
Security update available for Adobe Substance 3D Painter
Adobe Bulletin Not listed 2026-08-25
APSB26-134 ↗
Security update available for Adobe Campaign Classic
Adobe Bulletin Not listed 2026-08-25
Chrome 152.0.7977.64 ↗
Stable Channel Update for Desktop — 152.0.7977.64
Chrome Critical CVE-2026-78891, CVE-2026-78892, CVE-2026-78893, CVE-2026-78894, CVE-2026-78895, CVE-2026-78896, CVE-2026-78897, CVE-2026-78898, CVE-2026-78899, CVE-2026-78900, CVE-2026-78901, CVE-2026-78903, CVE-2026-78904, CVE-2026-78905, CVE-2026-78906, CVE-2026-78907, CVE-2026-78908, CVE-2026-78909, CVE-2026-78910, CVE-2026-78911, CVE-2026-78912, CVE-2026-78913, CVE-2026-78914, CVE-2026-78915, CVE-2026-78934, CVE-2026-78935, CVE-2026-78936, CVE-2026-78937, CVE-2026-78938, CVE-2026-78939, CVE-2026-78940, CVE-2026-78941, CVE-2026-78942, CVE-2026-78943, CVE-2026-78944, CVE-2026-78945, CVE-2026-78946, CVE-2026-78947, CVE-2026-78948, CVE-2026-78949, CVE-2026-78950, CVE-2026-78951, CVE-2026-78952, CVE-2026-78953, CVE-2026-78954, CVE-2026-78955, CVE-2026-78956, CVE-2026-78957, CVE-2026-78958, CVE-2026-78959, CVE-2026-78960, CVE-2026-78961, CVE-2026-78962, CVE-2026-78963, CVE-2026-78964, CVE-2026-78965, CVE-2026-78966, CVE-2026-78967, CVE-2026-78968, CVE-2026-78969, CVE-2026-78974, CVE-2026-78975, CVE-2026-78976, CVE-2026-78977, CVE-2026-78978, CVE-2026-78979, CVE-2026-78980, CVE-2026-78981, CVE-2026-78983, CVE-2026-78984, CVE-2026-78985, CVE-2026-78986, CVE-2026-78987, CVE-2026-78989, CVE-2026-78990, CVE-2026-78991, CVE-2026-78999, CVE-2026-79000, CVE-2026-79001, CVE-2026-79002, CVE-2026-79003, CVE-2026-79004, CVE-2026-79005, CVE-2026-79006, CVE-2026-79007, CVE-2026-79008, CVE-2026-79009, CVE-2026-79010, CVE-2026-79011, CVE-2026-79012, CVE-2026-79013, CVE-2026-79014, CVE-2026-79015, CVE-2026-79016, CVE-2026-79017, CVE-2026-79018, CVE-2026-79019, CVE-2026-79020, CVE-2026-79021, CVE-2026-79022, CVE-2026-79023, CVE-2026-79024, CVE-2026-79025, CVE-2026-79026, CVE-2026-79027, CVE-2026-79028, CVE-2026-79030, CVE-2026-79031, CVE-2026-79032, CVE-2026-79033, CVE-2026-79034, CVE-2026-79038, CVE-2026-79039, CVE-2026-79040, CVE-2026-79041, CVE-2026-79042, CVE-2026-79043, CVE-2026-79044, CVE-2026-79045, CVE-2026-79046, CVE-2026-79047, CVE-2026-79048, CVE-2026-79049, CVE-2026-79050, CVE-2026-79051, CVE-2026-79052, CVE-2026-79053, CVE-2026-79054, CVE-2026-79055, CVE-2026-79056, CVE-2026-79057, CVE-2026-79058, CVE-2026-79059, CVE-2026-79060, CVE-2026-79064, CVE-2026-79065, CVE-2026-79066, CVE-2026-79067, CVE-2026-79068, CVE-2026-79069, CVE-2026-79070, CVE-2026-79071, CVE-2026-79072, CVE-2026-79073, CVE-2026-79074, CVE-2026-79075, CVE-2026-79076, CVE-2026-79077, CVE-2026-79078, CVE-2026-79082, CVE-2026-79083, CVE-2026-79084, CVE-2026-79085, CVE-2026-79086, CVE-2026-79087, CVE-2026-79088, CVE-2026-79089, CVE-2026-79090, CVE-2026-79091, CVE-2026-79093, CVE-2026-79094, CVE-2026-79095, CVE-2026-79097, CVE-2026-79098, CVE-2026-79099, CVE-2026-79103, CVE-2026-79104, CVE-2026-79105, CVE-2026-79106, CVE-2026-79107, CVE-2026-79108, CVE-2026-79109, CVE-2026-79110, CVE-2026-79111, CVE-2026-79112, CVE-2026-79116, CVE-2026-79117, CVE-2026-79118, CVE-2026-79119, CVE-2026-79120, CVE-2026-79121, CVE-2026-79122, CVE-2026-79123, CVE-2026-79124, CVE-2026-79125, CVE-2026-79126, CVE-2026-79127, CVE-2026-79128, CVE-2026-79129, CVE-2026-79130, CVE-2026-79131, CVE-2026-79132, CVE-2026-79133, CVE-2026-79134, CVE-2026-79136, CVE-2026-79137, CVE-2026-79138, CVE-2026-79139, CVE-2026-79140, CVE-2026-79141, CVE-2026-79142, CVE-2026-79143, CVE-2026-79144, CVE-2026-79146, CVE-2026-79147, CVE-2026-79148, CVE-2026-79149, CVE-2026-79150, CVE-2026-79151, CVE-2026-79152, CVE-2026-79154, CVE-2026-79155, CVE-2026-79173, CVE-2026-79174, CVE-2026-79175, CVE-2026-79176, CVE-2026-79177, CVE-2026-79178, CVE-2026-79179, CVE-2026-79180, CVE-2026-79181, CVE-2026-79182, CVE-2026-79183, CVE-2026-79184, CVE-2026-79185, CVE-2026-79186, CVE-2026-79187, CVE-2026-79188, CVE-2026-79189, CVE-2026-79190, CVE-2026-79191, CVE-2026-79192, CVE-2026-79193, CVE-2026-79194, CVE-2026-79195, CVE-2026-79196, CVE-2026-79197, CVE-2026-79198, CVE-2026-79199, CVE-2026-79200, CVE-2026-79201, CVE-2026-79202, CVE-2026-79203, CVE-2026-79204, CVE-2026-79205, CVE-2026-79206, CVE-2026-79207, CVE-2026-79208, CVE-2026-79209, CVE-2026-79210, CVE-2026-79211, CVE-2026-79212, CVE-2026-79213, CVE-2026-79214, CVE-2026-79215, CVE-2026-79216, CVE-2026-79217, CVE-2026-79218, CVE-2026-79219, CVE-2026-79220, CVE-2026-79221, CVE-2026-79222, CVE-2026-79223, CVE-2026-79224, CVE-2026-79225, CVE-2026-79226, CVE-2026-79227, CVE-2026-79228, CVE-2026-79229, CVE-2026-79230, CVE-2026-79231, CVE-2026-79232, CVE-2026-79233, CVE-2026-79234, CVE-2026-79235, CVE-2026-79236, CVE-2026-79237, CVE-2026-79238, CVE-2026-79239, CVE-2026-79240, CVE-2026-79241, CVE-2026-79242, CVE-2026-79243, CVE-2026-79244, CVE-2026-79245, CVE-2026-79246, CVE-2026-79247, CVE-2026-79248, CVE-2026-79249, CVE-2026-79250, CVE-2026-79251, CVE-2026-79252, CVE-2026-79253, CVE-2026-79254, CVE-2026-79255, CVE-2026-79256, CVE-2026-79257, CVE-2026-79258, CVE-2026-79259, CVE-2026-79260, CVE-2026-79261, CVE-2026-79262, CVE-2026-79263, CVE-2026-79264, CVE-2026-79265, CVE-2026-79266, CVE-2026-79267, CVE-2026-79269, CVE-2026-79270, CVE-2026-79271, CVE-2026-79272, CVE-2026-79273, CVE-2026-79274, CVE-2026-79275, CVE-2026-79276, CVE-2026-79282, CVE-2026-79283, CVE-2026-79284, CVE-2026-79285, CVE-2026-79286, CVE-2026-79287, CVE-2026-79288, CVE-2026-79289, CVE-2026-79290, CVE-2026-79291, CVE-2026-79292, CVE-2026-79293 2026-08-25
Chrome 151.0.7922.173 ↗
Stable Channel Update for Desktop — 151.0.7922.173
Chrome Critical CVE-2026-76017, CVE-2026-76018, CVE-2026-76019, CVE-2026-76020, CVE-2026-76021, CVE-2026-76022, CVE-2026-76023 2026-08-20
cisco-sa-hardening-crosswork-UzDTU9Vh ↗
Cisco Crosswork Security Hardening Release: August 2026
Cisco Critical CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359 2026-08-19
cisco-sa-ie1k-uxq86Lnx ↗
Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability
Cisco Medium CVE-2026-20177 2026-08-19
cisco-sa-roomos-bof-vTMANZgu ↗
Cisco RoomOS Stack Overflow Vulnerability
Cisco Medium CVE-2026-20302 2026-08-19
cisco-sa-bworks-xxe-uwUd7CEt ↗
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
Cisco High CVE-2026-20320 2026-08-19
cisco-sa-hardening-csw1-shSvndWP ↗
Cisco Secure Workload Software Security Hardening Release: August 2026
Cisco Critical CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319 2026-08-19
cisco-sa-ie1k-NgXUFF52 ↗
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Cisco Medium CVE-2026-20232 2026-08-19
cisco-sa-ucce-pcce-ssrf-TghHxD ↗
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
Cisco Medium CVE-2026-20314 2026-08-19
cisco-sa-cuic-sql-inject-2qbfWSm5 ↗
Cisco Unified Intelligence Center SQL Injection Vulnerability
Cisco Medium CVE-2026-20327 2026-08-19
CSPUAug2026 ↗
Oracle Critical Security Patch Update Advisory - August 2026
Oracle Critical Security Patch Update Not listed 2026-08-18

Microsoft lifecycle milestones

30 of 185 matching, 226 products tracked. A product past its end of support stops receiving the fixes the rest of this page is about.

ProductReleaseMilestoneDate
Visual Studio ↗ 2026 - 18.8 End of life 2026-08-11
SharePoint Server ↗ 2019 End of life 2026-07-14
SharePoint Server ↗ 2016 End of life 2026-07-14
Visual Studio ↗ 2026 - 18.7 End of life 2026-07-14
Visual Studio ↗ 2022 - 17.12 (LTSC) End of life 2026-07-14
Visual Studio ↗ 2026 - 18.6 End of life 2026-06-09
Windows Server ↗ Windows Server 23H2 AC End of life 2026-05-12
Visual Studio ↗ 2026 - 18.5 End of life 2026-05-12
Visual Studio ↗ 2026 - 18.4 End of life 2026-04-14
Visual Studio ↗ 2026 - 18.3 End of life 2026-03-10
Visual Studio ↗ 2026 - 18.2 End of life 2026-02-10
Visual Studio ↗ 2026 - 18.1 End of life 2026-01-13
Visual Studio ↗ 2022 - 17.10 (LTSC) End of life 2026-01-13
Visual Studio ↗ 2026 - 18.0 End of life 2025-12-09
Windows (Client) ↗ 11 23H2 (W) End of life 2025-11-11
Windows (Client) ↗ 11 22H2 (E) End of life 2025-10-14
Windows (Client) ↗ 10 1507 (E) (LTS) End of life 2025-10-14
Office ↗ 2019 End of life 2025-10-14
Office ↗ 2016 End of life 2025-10-14
Visual Studio ↗ 2015 - 14.0 End of life 2025-10-14
SQL Server ↗ 2012 'Denali' SP4 Extended security updates ended 2025-07-08
Visual Studio ↗ 2022 - 17.8 (LTSC) End of life 2025-07-08
Visual Studio ↗ 2022 - 17.13 End of life 2025-05-13
Visual Studio ↗ 2022 - 17.6 (LTSC) End of life 2025-01-14
.NET ↗ 6 (LTS) End of life 2024-11-12
Visual Studio ↗ 2022 - 17.11 End of life 2024-11-12
PowerShell ↗ 7.2 (LTS) End of life 2024-11-08
Windows (Client) ↗ 11 22H2 (W) End of life 2024-10-08
Windows (Client) ↗ 11 21H2 (E) End of life 2024-10-08
Visual Studio ↗ 2022 - 17.4 (LTSC) End of life 2024-07-09

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.