VENDOR

Microsoft vulnerabilities: CVEs, exploitation and patches (page 5)

Every Microsoft CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-66804
    Windows 10 Version 22H2 cross-device service local privilege escalation Microsoft Windows 10 Version 22H2 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  2. CVE-2026-69328
    Windows 10 Version 1607 untrusted search path local privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7.8
  3. CVE-2026-62911
    Microsoft Exchange Server authentication bypass (capture-replay) Microsoft Microsoft Exchange Server 2016 Cumulative Update 23 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8
  4. CVE-2026-50338
    Azure Spring Apps improper authentication privilege escalation Microsoft Azure Spring Apps ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.2
  5. CVE-2026-50369
    Windows 10 Version 1607 Remote Desktop Services use-after-free elevation of privilege Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  6. CVE-2026-54121
    Windows 10 AD CS improper authorization privilege escalation Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  7. CVE-2026-49179
    Windows Active Directory command injection remote code execution Microsoft Windows 10 Version 1607 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  8. CVE-2026-63520
    Microsoft SharePoint Enterprise Server 2016 improper input validation RCE Microsoft Microsoft SharePoint Enterprise Server 2016 ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  9. CVE-2026-56155
    Active Directory Federation Services insufficient access control local privilege elevation Microsoft Active Directory Federation Services ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  10. CVE-2019-1068
    SQL Server remote code execution in internal function handling Microsoft SQL Server ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    HIGH 8.8
  11. CVE-2026-68820
    Windows Ancillary Function Driver for WinSock use-after-free local privilege escalation Microsoft Windows Ancillary Function Driver for WinSock ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 7
  12. CVE-2026-81963
    Windows local privilege escalation in Windows Update Stack (link following) Microsoft Windows ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  13. CVE-2026-85880
    Windows ALPC heap overflow local privilege escalation Microsoft Windows ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.8
  14. CVE-2026-45659
    SharePoint Server deserialization flaw allows authenticated remote code execution Microsoft SharePoint Server ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  15. CVE-2026-33824
    Internet Key Exchange (IKE) Service Extensions double free remote code execution Microsoft Internet Key Exchange (IKE) Service Extensions ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  16. CVE-2026-50522
    SharePoint deserialization pre-auth remote code execution Microsoft SharePoint ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  17. CVE-2026-56164
    SharePoint Server missing authentication allows privilege elevation Microsoft SharePoint Server ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
  18. CVE-2026-55040
    SharePoint weak authentication pre-auth bypass vulnerability Microsoft SharePoint ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.1
  19. CVE-2026-58644
    SharePoint deserialization remote code execution Microsoft SharePoint ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    CRITICAL 9.8
  20. CVE-2026-65660
    code injection in SharePoint server allowing remote code execution Microsoft SharePoint ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
20 CVEs · page 5 of 5