Known Vulnerabilities for products from Microsoft
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Microsoft".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Microsoft can be found at device.report : Microsoft
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76037 json | Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to poten... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-74801 json | Not Provided | 2026-08-17 | 2026-08-17 | |
| CVE-2026-73298 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-73297 json | Not Provided | 2026-08-12 | 2026-08-12 | |
| CVE-2026-73296 json | Not Provided | 2026-08-12 | 2026-08-13 | |
| CVE-2026-73217 json | Not Provided | 2026-08-11 | 2026-08-11 | |
| CVE-2026-72971 json | Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) ... | Not Provided | 2026-08-11 | 2026-08-14 |
| CVE-2026-72970 json | Not Provided | 2026-08-14 | 2026-08-17 | |
| CVE-2026-71331 json | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code ove... | Not Provided | 2026-08-11 | 2026-08-20 |
| CVE-2026-70355 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-70354 json | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | Not Provided | 2026-08-11 | 2026-08-17 |
| CVE-2026-70348 json | Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker t... | Not Provided | 2026-08-11 | 2026-08-14 |
| CVE-2026-70347 json | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-70346 json | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-70345 json | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-70344 json | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-70340 json | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-08-11 | 2026-08-17 |
| CVE-2026-70339 json | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attac... | Not Provided | 2026-08-11 | 2026-08-17 |
| CVE-2026-70338 json | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a... | Not Provided | 2026-08-11 | 2026-08-14 |
| CVE-2026-70337 json | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-08-11 | 2026-08-14 |
Known software with vulnerabilities from Microsoft
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Microsoft | .net Core | 1.0 |
| Application | Microsoft | .net Framework | - |
| Application | Microsoft | .net Windows Server | - |
| Application | Microsoft | 365 Apps | - |
| Application | Microsoft | 3d Viewer | - |
| Application | Microsoft | Access | - |
| Application | Microsoft | Access Multilingual User Interface Pack | 2007 |
| Application | Microsoft | Activesync | - |
| Application | Microsoft | Activex | - |
| Application | Microsoft | Active Directory | - |
| Application | Microsoft | Active Directory Application Mode | - |
| Application | Microsoft | Active Directory Federation Services | 1.0 |
| Application | Microsoft | Active Directory Lightweight Directory Service | - |
| Application | Microsoft | Active Directory Services | - |
| Application | Microsoft | Ampx | - |
| Application | Microsoft | Antigen | - |
| Application | Microsoft | Antispyware | - |
| Application | Microsoft | Applicationinspector | 1.0.1 |
| Application | Microsoft | Application Inspector | 1.0.23 |
| Application | Microsoft | Asp.net | - |