VENDOR

Microsoft vulnerabilities: CVEs, exploitation and patches (page 3)

Every Microsoft CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-70296
    Windows 10 Version 1607 out-of-bounds write in Windows Imaging Component Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-72950
    Windows Routing and Remote Access Service remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  3. CVE-2026-72979
    Windows 10 Version 1607 DHCP Server use-after-free remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  4. CVE-2026-72982
    Windows 10 Version 1607 Netlogon stack-based buffer overflow remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  5. CVE-2026-72983
    Windows Internet Connection Sharing use-after-free remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  6. CVE-2026-73009
    Windows Secure Socket Tunneling Protocol use-after-free remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  7. CVE-2026-73010
    Windows 10 Version 1809 use-after-free remote code execution Microsoft Windows 10 Version 1809 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  8. CVE-2026-73025
    Windows iSCSI weak authentication network bypass Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  9. CVE-2026-77493
    Windows 10 Version 1607 double-free in Graphics Component allows remote code execution Microsoft Windows 10 Version 1607 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  10. CVE-2026-78445
    Windows Server Services for NFS use-after-free remote code execution Microsoft Windows Server 2012 ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  11. CVE-2026-69399
    Azure ARC elevation of privilege via network Microsoft Azure ARC ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  12. CVE-2026-70009
    Azure ARC path traversal privilege elevation Microsoft Azure ARC ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  13. CVE-2026-70200
    Azure Logic Apps path traversal allows remote privilege escalation Microsoft Azure Logic Apps ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  14. CVE-2026-85889
    Azure AI Foundry missing authentication privilege elevation Microsoft Azure AI Foundry ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  15. CVE-2026-57983
    Microsoft Edge security feature bypass over network (pre-auth authorization bypass) Microsoft Microsoft Edge (Chromium-based) ·
    • PATCH AVAILABLE
    CRITICAL 10
  16. CVE-2026-56163
    Azure Kubernetes Service missing authentication allows pre-auth privilege escalation Microsoft Azure Kubernetes Service ·
    • PATCH AVAILABLE
    CRITICAL 10
  17. CVE-2026-66803
    Azure Cosmos DB improper access control pre-auth remote code execution Microsoft Azure Cosmos DB ·
    • PATCH AVAILABLE
    CRITICAL 10
  18. CVE-2026-56162
    Azure SQL Database improper authentication privilege elevation Microsoft Azure SQL Database ·
    • PATCH AVAILABLE
    CRITICAL 10
  19. CVE-2026-62836
    Azure SQL Managed Instance privilege elevation via communication channel flaw Microsoft Azure SQL Managed Instance ·
    • PATCH AVAILABLE
    CRITICAL 10
  20. CVE-2026-65667
    Microsoft Teams missing authorization privilege elevation Microsoft Microsoft Teams ·
    • PATCH AVAILABLE
    CRITICAL 10
20 CVEs · page 3 of 5