VENDOR

Microsoft vulnerabilities: CVEs, exploitation and patches

Every Microsoft CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-67378
    Microsoft SQL Server untrusted pointer dereference leads to remote code execution Microsoft Microsoft SQL Server 2019 (CU 32) ·
    • PATCH AVAILABLE
    CRITICAL 9
  2. CVE-2026-67636
    Microsoft SQL Server out-of-bounds read leads to remote code execution Microsoft Microsoft SQL Server 2019 (CU 32) ·
    • PATCH AVAILABLE
    CRITICAL 9
  3. CVE-2026-62916
    Microsoft Entra authentication bypass lets unauthenticated attacker elevate privileges Microsoft Microsoft Entra ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-67631
    Microsoft SQL Server heap-based buffer overflow allows remote code execution Microsoft Microsoft SQL Server 2017 (CU 31) ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-67643
    Microsoft SQL Server 2022/2025 heap buffer overflow pre-auth remote code execution Microsoft Microsoft SQL Server 2022 (CU 26) ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-78509
    Microsoft 365 Apps heap buffer overflow remote code execution Microsoft Microsoft 365 Apps for Enterprise ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-81352
    Web Media Extensions heap buffer overflow allows pre-auth remote code execution Microsoft Web Media Extensions ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  8. CVE-2026-66302
    Skype for Business Server remote code execution via file path control Microsoft Skype for Business Server 2015 CU13 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-80098
    Microsoft Copilot Studio signature verification flaw allows remote privilege escalation Microsoft Microsoft Copilot Studio ·
    • PATCH AVAILABLE
    CRITICAL 10
  10. CVE-2026-83711
    Entra authorization bypass via user-controlled key Microsoft Entra ·
    • PATCH AVAILABLE
    CRITICAL 10
  11. CVE-2026-69843
    Microsoft Fabric authentication bypass by spoofing allows privilege elevation Microsoft Microsoft Fabric ·
    • PATCH AVAILABLE
    CRITICAL 10
  12. CVE-2026-83944
    Azure Logic Apps pre-auth privilege escalation via improper access control Microsoft Azure Logic Apps ·
    • PATCH AVAILABLE
    CRITICAL 9.1
  13. CVE-2026-62815
    Windows 11 use-after-free in Microsoft QUIC allows remote code execution Microsoft Windows 11 version 23H2 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-62878
    Windows Server DNS stack buffer overflow remote code execution Microsoft Windows Server 2012 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-62893
    Windows Server use-after-free in Windows Deployment Services allows remote code execution Microsoft Windows Server 2012 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  16. CVE-2026-65768
    Microsoft Teams for Android path traversal pre-auth remote code execution Microsoft Microsoft Teams for Android ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  17. CVE-2026-65791
    Windows iSCSI Target heap buffer overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  18. CVE-2026-62834
    Azure Data Factory improper signature verification allows privilege elevation Microsoft Azure Data Factory ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  19. CVE-2026-68839
    Windows USB Mass Storage heap overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  20. CVE-2026-69276
    Windows UxTheme integer underflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
20 CVEs · page 1 of 5