Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 7/380
5.5
CVE-2026-62786

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

8.8
CVE-2026-62785

Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to ex

8.8
CVE-2026-62784

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execut

7.8
CVE-2026-62783

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileg

6.5
CVE-2026-62782

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

8.1
CVE-2026-62781

Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.

7.0
CVE-2026-62780

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62779

Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.

8.1
CVE-2026-62778

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

7.8
CVE-2026-62777

Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privile

7.8
CVE-2026-62776

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to e

5.5
CVE-2026-62775

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to d

7.0
CVE-2026-62774

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62773

Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62772

Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker t

7.8
CVE-2026-62771

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges

7.8
CVE-2026-62770

Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-62769

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62768

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62766

Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62761

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to e

7.8
CVE-2026-62758

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileg

5.3
CVE-2026-62757

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit

7.8
CVE-2026-62755

Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62754

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62753

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62752

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62751

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca

6.5
CVE-2026-62750

Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad

7.0
CVE-2026-62749

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62748

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.8
CVE-2026-62747

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges loc

5.5
CVE-2026-62746

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

6.5
CVE-2026-62745

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

5.5
CVE-2026-62743

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

6.5
CVE-2026-62742

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

7.8
CVE-2026-62741

Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

5.5
CVE-2026-62740

Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally

7.8
CVE-2026-62739

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

5.5
CVE-2026-62738

Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

7.8
CVE-2026-62737

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62736

Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62735

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-62734

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.8
CVE-2026-62733

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-62732

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

5.5
CVE-2026-62730

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

7.0
CVE-2026-62729

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.0
CVE-2026-62728

Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker

7.0
CVE-2026-62726

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 54122 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 54122 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started