Known Vulnerabilities for products from Microsoft
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Microsoft".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Microsoft can be found at device.report : Microsoft
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62835 json | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | Not Provided | 2026-07-24 | 2026-07-29 |
| CVE-2026-62828 json | Not Provided | 2026-07-28 | 2026-07-28 | |
| CVE-2026-62826 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an... | Not Provided | 2026-07-16 | 2026-07-22 |
| CVE-2026-61371 json | Not Provided | 2026-07-15 | 2026-07-15 | |
| CVE-2026-59864 json | Not Provided | 2026-07-16 | 2026-07-17 | |
| CVE-2026-59841 json | A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 t... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-59162 json | Not Provided | 2026-07-10 | 2026-07-10 | |
| CVE-2026-59161 json | Not Provided | 2026-07-10 | 2026-07-14 | |
| CVE-2026-59117 json | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-07-16 | 2026-07-30 |
| CVE-2026-58647 json | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacke... | Not Provided | 2026-07-14 | 2026-07-17 |
| CVE-2026-58644 json | Not Provided | 2026-07-14 | 2026-07-17 | |
| CVE-2026-58643 json | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauth... | Not Provided | 2026-07-16 | 2026-07-22 |
| CVE-2026-58640 json | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-58638 json | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-58637 json | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-58636 json | Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate ... | Not Provided | 2026-07-14 | 2026-07-17 |
| CVE-2026-58635 json | Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an aut... | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-58634 json | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-58633 json | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-58632 json | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-07-14 | 2026-07-22 |
Known software with vulnerabilities from Microsoft
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Microsoft | .net Core | 1.0 |
| Application | Microsoft | .net Framework | - |
| Application | Microsoft | .net Windows Server | - |
| Application | Microsoft | 365 Apps | - |
| Application | Microsoft | 3d Viewer | - |
| Application | Microsoft | Access | - |
| Application | Microsoft | Access Multilingual User Interface Pack | 2007 |
| Application | Microsoft | Activesync | - |
| Application | Microsoft | Activex | - |
| Application | Microsoft | Active Directory | - |
| Application | Microsoft | Active Directory Application Mode | - |
| Application | Microsoft | Active Directory Federation Services | 1.0 |
| Application | Microsoft | Active Directory Lightweight Directory Service | - |
| Application | Microsoft | Active Directory Services | - |
| Application | Microsoft | Ampx | - |
| Application | Microsoft | Antigen | - |
| Application | Microsoft | Antispyware | - |
| Application | Microsoft | Applicationinspector | 1.0.1 |
| Application | Microsoft | Application Inspector | 1.0.23 |
| Application | Microsoft | Asp.net | - |