Vendor
Microsoft vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 3,192 vulnerabilities in Microsoft: 28 in the last 7 days and 1,975 in the last 90 days, 634 of them critical and 441 exploited in the wild. The most recent, CVE-2026-83964, was published on 22 September 2026. 174 technologies have a page of their own.
- Last 7 days
- 28
- Last 90 days
- 1,975
- Critical, all time
- 634
- Exploited in the wild
- 441
About Microsoft
American multinational technology corporation that develops software, cloud services, and hardware products.
Microsoft technologies
- Microsoft Windows963
- Microsoft Windows 10588
- Microsoft Windows 11493
- Microsoft Windows Server 2012293
- Microsoft Windows Server 2016213
- Microsoft Windows Server 2019211
- Microsoft Windows 11 24h2192
- Microsoft Windows Server 2022178
- Microsoft Edge167
- Microsoft Windows 11 25h2161
- Microsoft Windows 11 Version 26H1135
- Microsoft Windows Server 2025124
- Microsoft Windows Server 2008116
- Microsoft Windows 10 21h2105
- Microsoft Windows 10 22h2105
- Microsoft Office103
- Microsoft Windows 7100
- Microsoft Windows 8.1100
- Microsoft Windows 10 180989
- Microsoft 365 Apps for Enterprise84
- Microsoft Office LTSC 202182
- Microsoft Office LTSC 202482
- Microsoft Office 201979
- Microsoft Windows 10 160767
- Microsoft SQL Server65
- Microsoft Windows Rt 8.165
- Microsoft Office 365 for Mac64
- Microsoft Exchange Server52
- Microsoft Internet Explorer49
- Microsoft Office Excel49
- Microsoft Office Word49
- Microsoft Office LTSC for Mac 202145
- Microsoft Office LTSC for Mac 202445
- Microsoft Windows Vista42
- Microsoft Office 201640
- Microsoft Windows 11 23h240
- Microsoft SharePoint Server 201937
- Microsoft Visual-Studio-Code37
- Microsoft SharePoint36
- Microsoft Windows NT35
- Microsoft SharePoint Enterprise Server 201634
- Microsoft Windows Biometric Service34
- Microsoft Office Online Server33
- Microsoft SharePoint Server Subscription Edition32
- Microsoft Edge Chromium31
- Microsoft Excel 201631
- Microsoft Office SharePoint31
- Microsoft Windows DHCP Server31
- Microsoft Sharepoint-Server30
- Microsoft Windows Server 2012 R229
- Microsoft Word29
- Microsoft Windows Server 2022, 23H227
- Microsoft Win32K25
- Microsoft Excel24
- Microsoft Remote Desktop Client22
- Microsoft Windows Dns Server20
- Microsoft Windows Server 2008 R220
- Microsoft Windows 200019
- Microsoft Visual Studio 202217
- Microsoft .NET Framework16
- Microsoft Standard XPS16
- Microsoft Visual Studio16
- Microsoft Windows Server16
- Microsoft 365 Copilot12
- Microsoft Windows Kernel12
- Microsoft Windows NTFS12
- Microsoft Kiota11
- Microsoft.OpenApi.Kiota11
- Microsoft Office for Android11
- Microsoft Skype for Business11
- Microsoft Windows Admin Center11
- Microsoft Active Directory Federation Services10
- Microsoft Entra ID10
- Microsoft.OpenApi.Kiota.Builder10
- Microsoft Office Access10
- Microsoft Active Directory Domain Services9
- Microsoft Asp.net Core9
- Microsoft UFO9
- Microsoft Defender8
- Microsoft Graphics Component8
- Microsoft Hyper-V8
- Microsoft M365 Copilot8
- Microsoft Office PowerPoint8
- Microsoft SharePoint Server 2016 Enterprise Edition8
- Microsoft SQL Server 20258
- Microsoft Dynamics 3657
- Microsoft Windows 957
- Microsoft Windows Autopilot7
- Microsoft Windows Imaging Component7
- Microsoft Windows Message Queuing7
- Microsoft Windows Print Spooler7
- Microsoft Windows Push Notifications7
- Microsoft Edge (Chromium-based) for Android6
- Microsoft Exchange Server Subscription Edition6
- Microsoft .NET Core6
- Microsoft Office Outlook6
- Microsoft Outlook6
- Microsoft PowerPoint6
- Microsoft SQL Server 20226
- Microsoft Windows Overlay Filter6
- Microsoft Windows Remote Desktop Services6
- Microsoft Windows Services for NFS6
- Microsoft Azure Arc5
- Microsoft Azure Sql Database5
- Microsoft Exchange Online5
- Microsoft Exchange Server 20165
- Microsoft Exchange Server 20195
- Microsoft Internet Information Services5
- Microsoft Internet Information Services (Iis)5
- Microsoft PC Manager5
- Microsoft SQL Server 20165
- Microsoft SQL Server 20175
- Microsoft SQL Server 20195
- Microsoft Teams for Android5
- Microsoft Windows 11 22h25
- Microsoft Windows Hello5
- Microsoft Windows Hyper-V5
- Microsoft Windows Installer5
- Microsoft Windows Presentation Foundation5
- Microsoft Windows Remote Access Connection Manager5
- Microsoft Windows Search Component5
- Microsoft Windows Secure Boot5
- Microsoft Active Directory4
- Microsoft Azure Cosmos DB4
- Microsoft Azure CycleCloud4
- Microsoft Dynamics 365 (on-premises)4
- Microsoft Malware Protection Engine4
- Microsoft Office Click-to-Run4
- Microsoft Open Management Infrastructure (OMI)4
- Microsoft Teams4
- Microsoft Windows 11 26h14
- Microsoft Windows Ancillary Function Driver for WinSock4
- Microsoft Windows Deployment Services4
- Microsoft Windows Error Reporting4
- Microsoft Windows iSCSI Target Service4
- Microsoft Windows Media Foundation4
- Microsoft Windows Modern Device Management4
- Microsoft Windows Presentation Foundation (WPF)4
- Microsoft Windows Shell4
- Microsoft Windows SMB Client4
- Microsoft 365 Apps3
- Microsoft Apm-Cli3
- Microsoft Azure-Kubernetes-Service3
- Microsoft Azure Logic Apps3
- Microsoft BitLocker3
- Microsoft Configuration Manager3
- Microsoft DiaSymReader.Native3
- Microsoft Kiota.Builder3
- Microsoft MSHTML3
- Microsoft .NET Core Runtime3
- Microsoft Power Automate3
- Microsoft Power BI Report Server3
- Microsoft PowerPoint 20163
- Microsoft PowerShell3
- Microsoft Prompty3
- Microsoft Silverlight3
- Microsoft SQL Server 2016 Service Pack 3 (GDR)3
- Microsoft SQL Server 2017 (CU 31)3
- Microsoft SQL Server 2019 (CU 32)3
- Microsoft SQL Server 2022 (GDR)3
- Microsoft Windows Cloud Files Mini Filter Driver3
- Microsoft Windows Codecs Library3
- Microsoft Windows Failover Cluster3
- Microsoft Windows IKE Extension3
- Microsoft Windows Kerberos3
- Microsoft Windows Media Player3
- Microsoft Windows NT 4.03
- Microsoft Windows Remote Desktop Protocol3
- Microsoft Windows Server 20033
- Microsoft Windows Server Update Services (WSUS)3
- Microsoft Windows Storage Spaces Controller3
- Microsoft Windows USB Driver3
- Microsoft Windows XP3
- Microsoft XML Core Services3
Latest Microsoft vulnerabilities
- CVE-2026-83964: Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive…mediumCVSS 6.2EPSS 0.1%
- CVE-2026-75698: Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…criticalCVSS 9.3EPSS 0.3%
- CVE-2026-75697: Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to…criticalCVSS 9.3EPSS 0.3%
- CVE-2026-75689: Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to…criticalCVSS 9.3EPSS 0.3%
- CVE-2026-75686: Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in…criticalCVSS 9.3EPSS 1.1%
- CVE-2026-75684: Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to…criticalCVSS 9.3EPSS 0.3%
- CVE-2026-75682: Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…criticalCVSS 9.9EPSS 0.5%
- CVE-2026-48361: Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to…mediumCVSS 6.1EPSS 0.2%
- CVE-2026-34689: Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')…highCVSS 8.6EPSS 0.7%
- CVE-2026-89276: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 9.9EPSS 0.5%
- CVE-2026-89275: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-84412: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-83660: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…criticalCVSS 9.9EPSS 0.3%
- CVE-2026-82443: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…criticalCVSS 9.6EPSS 0.4%
- CVE-2026-82013: Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…criticalCVSS 9.9EPSS 0.8%
- CVE-2026-82011: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…criticalCVSS 9.1EPSS 0.5%
- CVE-2026-82010: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…criticalCVSS 9.9EPSS 1.0%
- CVE-2026-82009: Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL…criticalCVSS 9.1EPSS 1.0%
- CVE-2026-82008: Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code…criticalCVSS 9.9EPSS 0.5%
- CVE-2026-82003: Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code…highCVSS 8.5EPSS 0.9%
- CVE-2026-75728: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code…criticalCVSS 9.1EPSS 1.0%
- CVE-2026-75723: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code…criticalCVSS 10EPSS 1.2%
- CVE-2026-75721: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-75703: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
- CVE-2026-75699: Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability…criticalCVSS 10EPSS 1.3%
Most severe Microsoft vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2008-4250: Microsoft Windows buffer overflow in Server servicecriticalexploited in the wildCVSS 10EPSS 93.5%
- CVE-2020-0796: Microsoft SMBv3 Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2020-1350: Microsoft Windows DNS Server Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2020-1472: Microsoft Netlogon Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2025-53770: Microsoft SharePoint Server deserialization of untrusted datacriticalexploited in the wildCVSS 9.8EPSS 88.2%
- CVE-2024-43468: Microsoft Configuration Manager SQL injectioncriticalexploited in the wildCVSS 9.8EPSS 83.1%
- CVE-2025-59287: Microsoft Windows Server Update Service deserialization RCEcriticalexploited in the wildCVSS 9.8EPSS 71.4%
- CVE-2026-50522: Microsoft SharePoint remote code execution via unsafe deserializationcriticalexploited in the wildCVSS 9.8EPSS 20.3%
- CVE-2025-10585: Google Chrome type confusion in V8 enginecriticalexploited in the wildCVSS 9.8EPSS 5.4%
- CVE-2026-20963: Microsoft SharePoint deserialization of untrusted datacriticalexploited in the wildCVSS 9.8EPSS 5.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 50 | 4 | |
| 6 Jul 2026 | 4 | 1 | |
| 13 Jul 2026 | 592 | 22 | |
| 20 Jul 2026 | 20 | 11 | |
| 27 Jul 2026 | 2 | 1 | |
| 3 Aug 2026 | 13 | 0 | |
| 10 Aug 2026 | 175 | 5 | |
| 17 Aug 2026 | 23 | 12 | |
| 24 Aug 2026 | 35 | 7 | |
| 31 Aug 2026 | 29 | 5 | |
| 7 Sep 2026 | 980 | 49 | |
| 14 Sep 2026 | 24 | 11 | |
| 21 Sep 2026 | 28 | 22 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/microsoft.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft vulnerabilities", https://junglewise.ai/threats/vendors/microsoft, 26 September 2026.