VENDOR

Microsoft vulnerabilities: CVEs, exploitation and patches (page 4)

Every Microsoft CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-65770
    Azure Managed Instance for Apache Cassandra argument injection allows remote code execution Microsoft Azure Managed Instance for Apache Cassandra ·
    • PATCH AVAILABLE
    CRITICAL 10
  2. CVE-2026-65816
    Azure Web Apps incorrect name resolution lets unauthenticated actor elevate privileges Microsoft Azure Web Apps ·
    • PATCH AVAILABLE
    CRITICAL 10
  3. CVE-2026-69555
    Azure ARC incorrect authorization lets remote attacker escalate privileges Microsoft Azure ARC ·
    • PATCH AVAILABLE
    CRITICAL 10
  4. CVE-2026-69502
    Azure SQL Database server-side request forgery privilege elevation Microsoft Azure SQL Database ·
    • PATCH AVAILABLE
    CRITICAL 10
  5. CVE-2026-70352
    Azure AI Language Authoring missing authentication allows privilege elevation Microsoft Azure AI Language Authoring ·
    • PATCH AVAILABLE
    CRITICAL 10
  6. CVE-2026-69865
    Azure Container Registry authorization bypass via user-controlled key Microsoft Azure Container Registry ·
    • PATCH AVAILABLE
    CRITICAL 10
  7. CVE-2026-62874
    Azure Billing insufficient data authenticity privilege escalation Microsoft Azure Billing ·
    • PATCH AVAILABLE
    CRITICAL 10
  8. CVE-2026-69414
    Microsoft Malware Protection Engine elevation of privilege Microsoft Microsoft Malware Protection Engine ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  9. CVE-2026-54998
    Microsoft Exchange Online authorization bypass lets authorized users escalate privileges Microsoft Microsoft Exchange Online ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  10. CVE-2026-47301
    Microsoft Configuration Manager privilege escalation over network Microsoft Microsoft Configuration Manager ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  11. CVE-2026-54107
    Windows 10 Version 1607 race condition lets local users elevate privileges Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7
  12. CVE-2026-69451
    Windows 10 Version 1607 use-after-free in WMI allows privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.1
  13. CVE-2026-49176
    Windows 10/Server privilege escalation in WalletService (local) Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  14. CVE-2026-54992
    Windows 10 Version 1607 heap-based buffer overflow local code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  15. CVE-2026-58635
    Windows 10 Version 1809 Narrator Braille command injection local privilege elevation Microsoft Windows 10 Version 1809 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  16. CVE-2026-50343
    Windows Install Service local privilege escalation Microsoft Windows 10 Version 1809 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  17. CVE-2026-50402
    Windows NTFS numeric conversion local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  18. CVE-2026-54984
    Windows 10 Version 1607 heap buffer overflow local code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  19. CVE-2026-62735
    Windows HTTP.sys heap buffer overflow local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  20. CVE-2026-62737
    Windows 11 untrusted pointer dereference local privilege escalation Microsoft Windows 11 Version 24H2 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
20 CVEs · page 4 of 5