VENDOR
Microsoft vulnerabilities: CVEs, exploitation and patches (page 5)
Every Microsoft CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-66804
Windows 10 Version 22H2 cross-device service local privilege escalationHIGH 7.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-69328
Windows 10 Version 1607 untrusted search path local privilege escalationHIGH 7.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-62911
Microsoft Exchange Server authentication bypass (capture-replay)HIGH 8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-50338
Azure Spring Apps improper authentication privilege escalationHIGH 8.2
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-50369
Windows 10 Version 1607 Remote Desktop Services use-after-free elevation of privilegeHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-54121
Windows 10 AD CS improper authorization privilege escalationHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-49179
Windows Active Directory command injection remote code executionHIGH 8.8
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-63520
Microsoft SharePoint Enterprise Server 2016 improper input validation RCEHIGH 8.1
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-56155
Active Directory Federation Services insufficient access control local privilege elevationHIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2019-1068
SQL Server remote code execution in internal function handlingHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
-
CVE-2026-68820
Windows Ancillary Function Driver for WinSock use-after-free local privilege escalationHIGH 7
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-81963
Windows local privilege escalation in Windows Update Stack (link following)HIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-85880
Windows ALPC heap overflow local privilege escalationHIGH 7.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-45659
SharePoint Server deserialization flaw allows authenticated remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-33824
Internet Key Exchange (IKE) Service Extensions double free remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-50522
SharePoint deserialization pre-auth remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-56164
SharePoint Server missing authentication allows privilege elevationCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-55040
SharePoint weak authentication pre-auth bypass vulnerabilityCRITICAL 9.1
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
-
CVE-2026-58644
SharePoint deserialization remote code executionCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-65660
code injection in SharePoint server allowing remote code executionHIGH 8.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
20 CVEs · page 5 of 5