Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 16/380
7.8
CVE-2026-55048

Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

5.5
CVE-2026-55047

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55046

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

8.4
CVE-2026-55045

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55044

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55043

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

5.5
CVE-2026-55042

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

7.8
CVE-2026-55041

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

9.1
CVE-2026-55040 KEV

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n

7.8
CVE-2026-55039

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally

7.8
CVE-2026-55038

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55037

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55036

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

5.5
CVE-2026-55035

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

7.3
CVE-2026-55034

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

7.8
CVE-2026-55033

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55032

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55031

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

4.6
CVE-2026-55030

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

7.8
CVE-2026-55029

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

5.5
CVE-2026-55028

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-55027

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

6.2
CVE-2026-55026

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

7.8
CVE-2026-55025

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-55024

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

5.5
CVE-2026-55023

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

7.8
CVE-2026-55022

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe

7.3
CVE-2026-55021

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55020

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55019

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

7.8
CVE-2026-55018

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55017

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

4.6
CVE-2026-55016

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

9.8
CVE-2026-55010

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a

7.8
CVE-2026-54131

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-54128

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

6.5
CVE-2026-54126

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

7.8
CVE-2026-54125

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

7.8
CVE-2026-54124

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

8.8
CVE-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privile

6.5
CVE-2026-54116

Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in

7.8
CVE-2026-54115

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50692

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

5.5
CVE-2026-50690

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

7.8
CVE-2026-50689

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50688

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50687

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.1
CVE-2026-50686

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute

7.5
CVE-2026-50685

Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.

4.8
CVE-2026-50684

Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Serv

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started