Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 10/380
7.5
CVE-2026-54113

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o

9.4
CVE-2026-50516

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el

7.0
CVE-2026-50472

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-49179

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows a

7.2
CVE-2026-47299

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an aut

6.5
CVE-2026-47285

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau

7.8
CVE-2026-42976

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loca

6.5
CVE-2026-40375

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

9.6
CVE-2026-70332

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

9.1
CVE-2026-68823

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n

8.8
CVE-2026-65668

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo

10.0
CVE-2026-65667

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

10.0
CVE-2026-63508

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev

7.5
CVE-2026-62918

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing

9.6
CVE-2026-62896

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

9.8
CVE-2026-62873

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat

8.7
CVE-2026-62836

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized

9.9
CVE-2026-62830

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

9.3
CVE-2026-59118

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

9.9
CVE-2026-59115

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove

10.0
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

9.6
CVE-2026-56161

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

9.9
CVE-2026-50515

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

9.9
CVE-2026-50481

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privile

8.8
CVE-2026-49163

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a

9.6
CVE-2026-19171

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially per

8.3
CVE-2026-19163

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromise

7.5
CVE-2026-19158

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a us

7.4
CVE-2026-19139

Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-le

7.8
CVE-2026-18657

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac

7.8
CVE-2026-18656

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a

6.5
CVE-2026-66326

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

6.1
CVE-2026-66325

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin

7.1
CVE-2026-66322

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

7.4
CVE-2026-66321

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

8.1
CVE-2026-66318

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

5.4
CVE-2026-66317

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n

5.4
CVE-2026-66316

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

7.5
CVE-2026-66315

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

6.5
CVE-2026-66314

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to

6.8
CVE-2026-66313

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

6.5
CVE-2026-66312

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

6.2
CVE-2026-66311

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

7.7
CVE-2026-66310

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat

6.1
CVE-2026-65804

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta

7.4
CVE-2026-65802

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat

8.8
CVE-2026-62870

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-48399

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a

9.8
CVE-2026-48333

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca

10.0
CVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started