

Microsoft's monthly release, filterable
Patch Tuesday browser
Filter every CVE in Microsoft's latest Patch Tuesday by product, severity and impact. Search by CVE number, export what you filtered as CSV.
Microsoft publishes several hundred CVEs on the second Tuesday of each month, as a spreadsheet and a release note. Neither answers the question people actually arrive with, which is never “show me four hundred rows”. It is “what critical remote code execution landed on SharePoint”, or “is this CVE in this month”. This filters rather than prints, and the counts recompute as you filter, because the count is usually the answer.
Nothing leaves your browser: Everything happens in your browser against data already loaded with the page. No search term, filter or export leaves your machine, and this page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon. That rule does not govern images or a link you choose to follow, so what you do with a CVE number after you copy it is yours to protect. Nothing is stored either: a refresh loses your filters, and the CSV export is written by your own browser.
Start here
2 under active exploitation, 0 publicly disclosed before the fix. Everything else in this release can wait behind these.
- CVE-2026-81963 exploitedWindows Update Stack Elevation of Privilege Vulnerability · CVSS 7.8
- CVE-2026-85880 exploitedWindows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability · CVSS 7.8
973 shown of 973 · 113 Critical · 438 elevation of privilege · 2 under attack or disclosed9 entries in this release need no action from you: Microsoft has already fixed them service-side. Tick the box above to exclude them.
| CVE | Product | Impact | Severity | CVSS |
|---|---|---|---|---|
| CVE-2026-81963exploited | Windows Update StackWindows Update Stack Elevation of Privilege Vulnerability | Elevation of Privilege | ImportantExploitation Detected | 7.8 |
| CVE-2026-85880exploited | Windows ALPCWindows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Elevation of Privilege | ImportantExploitation Detected | 7.8 |
| CVE-2026-70352no action | Azure AI LanguageAzure AI Language Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 10.0 |
| CVE-2026-83711no action | Microsoft Azure Active Directory B2CMicrosoft Azure Active Directory B2C Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 10.0 |
| CVE-2026-83941no action | Entra IDEntra ID Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.9 |
| CVE-2026-66302 | Skype for BusinessSkype for Business Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-69579 | Windows Message QueuingWindows Message Queuing Remote Code Execution Vulnerability | Remote Code Execution | Critical | 9.8 |
| CVE-2026-69590 | Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-69595 | Windows Services for NFS ONCRPC XDR DriverWindows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-69730 | Windows DNSWindows DNS Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation More Likely | 9.8 |
| CVE-2026-69769 | Windows HTTP Print ProviderWindows HTTP Print Provider Remote Code Execution Vulnerability | Remote Code Execution | Critical | 9.8 |
| CVE-2026-69829 | Windows ShellWindows Shell Remote Code Execution Vulnerability | Remote Code Execution | Critical | 9.8 |
| CVE-2026-69845 | Windows DHCP ServerWindows DHCP Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-70296 | Windows Imaging ComponentWindows Imaging Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-72979 | Windows DHCP ServerWindows DHCP Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-72982 | Windows NetlogonWindows Netlogon Remote Code Execution Vulnerability | Remote Code Execution | Critical | 9.8 |
| CVE-2026-72983 | Windows Internet Connection Sharing (ICS)Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-73009 | Windows Secure Socket Tunneling Protocol (SSTP)Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-73010 | Windows Failover ClusterMicrosoft Failover Cluster Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-77493 | Microsoft Graphics ComponentWindows Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-78445 | Windows Services for NFS ONCRPC XDR DriverWindows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-78509 | Microsoft Office OutlookMicrosoft Office Outlook Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-78510 | Microsoft Office WordMicrosoft Word Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-65669 | SQL ServerMicrosoft SQL Server Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation Less Likely | 9.6 |
| CVE-2026-80098no action | Copilot StudioCopilot Studio Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.3 |
| CVE-2026-62916no action | Microsoft Entra IDMicrosoft Entra ID Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.1 |
| CVE-2026-69854 | Spring Cloud AzureSpring Cloud Azure Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation More Likely | 9.0 |
| CVE-2026-65772 | Microsoft Dynamics 365Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-67631 | SQL ServerMicrosoft SQL Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-67643 | SQL ServerMicrosoft SQL Server Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.8 |
| CVE-2026-69285 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69499 | Windows Imaging ComponentWindows Imaging Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69518 | Windows Remote DesktopWindows Remote Desktop Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69601 | Microsoft Windows Media FoundationMicrosoft Windows Media Foundation Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69603 | Windows Hyper-VWindows Hyper-V Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.8 |
| CVE-2026-69632 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69649 | Windows Raw Image ExtensionRaw Image Extension Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69676 | Windows KerberosWindows Kerberos Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation More Likely | 8.8 |
| CVE-2026-69678 | Microsoft Office PowerPointMicrosoft Office PowerPoint Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69712 | Windows Key Distribution CenterWindows Key Distribution Center Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69740 | Windows HelloWindows Hello Elevation of Privilege Vulnerability | Elevation of Privilege | Critical | 8.8 |
| CVE-2026-69767 | Microsoft Office PowerPointMicrosoft Office PowerPoint Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69784 | Windows HelloWindows Hello Elevation of Privilege Vulnerability | Elevation of Privilege | Critical | 8.8 |
| CVE-2026-69797 | Microsoft Office PowerPointMicrosoft Office PowerPoint Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-69860 | Windows Imaging ComponentWindows Imaging Component Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.8 |
| CVE-2026-70203 | Windows Media PlayerWindows Media Player Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-70351 | Microsoft WebP Image ExtensionMicrosoft WebP Image Extension Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.8 |
| CVE-2026-70586 | Windows PaintWindows Paint Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.8 |
| CVE-2026-72950 | Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.8 |
| CVE-2026-72959 | Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-72960 | Windows Media PlayerWindows Media Player Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.8 |
| CVE-2026-72986 | Graphic FontsGraphic Fonts Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-73006 | Microsoft Graphics ComponentDirectWrite Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-73013 | Windows Imaging ComponentWindows Imaging Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-73018 | Graphic FontsGraphic Fonts Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-73023 | Windows Imaging ComponentWindows Imaging Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-77495 | Windows Imaging ComponentWindows Imaging Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-77504 | Microsoft Office WordMicrosoft Office Word Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-78439 | Microsoft Graphics ComponentMicrosoft Office Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-78505 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
What this release looks like, before you filter it
Currently loaded: Microsoft’s 2026-Sep release, published , carrying 973 CVE numbers Microsoft assigned itself, of which 964 need something deploying. A further 197 come from Chromium and the open source packages inside Azure Linux, which Microsoft reships under the same release. Those are real, and they are in the table behind a checkbox, but they are not what anybody means by “this month’s Patch Tuesday”.
By severity
- Important860
- Critical113
By impact
- Elevation of Privilege438
- Remote Code Execution258
- Information Disclosure173
- Denial of Service56
- Security Feature Bypass19
- Spoofing16
- Tampering13
Elevation of privilege is the largest class in this release, ahead of remote code execution. That is worth reading twice before triaging by severity: it describes what an attacker does once they are already on the machine, and the only vulnerability Microsoft confirmed as exploited this month is one of them. The reasoning is in the briefing on this release.
Where the numbers come from
Built by script from Microsoft’s machine-readable document for this release, the same one that backs the September 2026 release note. Severity, impact, CVSS, exploitation status and the authority that assigned each number are Microsoft’s own classification, carried through unchanged. Nothing on this page is inferred, and the script that builds it is in the repository so the figures can be reproduced rather than believed.
Corrected on 12 August 2026. This tool first shipped with 438 CVEs for the August release, taken from a spreadsheet export. That export is a rolling thirty-day view rather than a single release, so it carried nineteen entries belonging to July or to old Dynamics re-releases. The correct figure for August was 420. It is recorded here rather than quietly fixed, because it is exactly the mistake the accompanying briefing accuses other people of making.
The whole release is available as JSON at /api/tools/patch-tuesday-2026-09.json, free to use with attribution.
Common questions
›Why do published CVE counts for the same Patch Tuesday disagree?
Because they are counting different things. Microsoft's September 2026 file carries 973 CVE numbers that Microsoft assigned itself, and 9 of them need no action from anybody: service-side fixes to Entra ID, Azure AI Language, Copilot Studio, Power Automate, Cosmos DB and Fabric that Microsoft had already deployed. Exclude those and the total is 964. A further 197 come from Chromium and the Azure Linux packages Microsoft reships, which takes the document to 1,170. All three numbers can be quoted honestly. None is wrong; state which basis you used.
›Should I patch by severity rating?
Not by severity alone. In the September 2026 release both vulnerabilities Microsoft confirms as exploited are rated Important rather than Critical and both score 7.8, because the rating weighs the requirement for local access. Sorting on severity puts them below 113 Critical entries that nobody is exploiting, two of which are rated 10.0 and need no action at all because Microsoft had already fixed them. Severity describes the vulnerability; it does not describe your estate.
›What does customer action required mean?
Microsoft marks entries where the fix is theirs to deploy rather than yours to install, typically in Azure, Teams or Microsoft 365. They still receive a CVE number and still appear in vulnerability reports, which quietly dilutes any remediation percentage that counts them. Use the checkbox above to exclude them when you are measuring patching effort.
›Which release does this cover?
September 2026, published on 8 September 2026. This page carries one release at a time rather than an archive, because the question it answers is about the month you are currently patching. The August 2026 dataset stays reachable at /api/tools/patch-tuesday-2026-08.json, so nothing that linked to it breaks.
When you need more than a tool
vCISO advisory
Embedded security leadership: board reporting, programme direction, and risk decisions taken with accountability and written down.
Read moreRelated analysis
