P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Microsoft's monthly release, filterable

Patch Tuesday browser

Filter every CVE in Microsoft's latest Patch Tuesday by product, severity and impact. Search by CVE number, export what you filtered as CSV.

Microsoft publishes several hundred CVEs on the second Tuesday of each month, as a spreadsheet and a release note. Neither answers the question people actually arrive with, which is never “show me four hundred rows”. It is “what critical remote code execution landed on SharePoint”, or “is this CVE in this month”. This filters rather than prints, and the counts recompute as you filter, because the count is usually the answer.

Nothing leaves your browser: Everything happens in your browser against data already loaded with the page. No search term, filter or export leaves your machine, and this page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon. That rule does not govern images or a link you choose to follow, so what you do with a CVE number after you copy it is yours to protect. Nothing is stored either: a refresh loses your filters, and the CSV export is written by your own browser.

Last reviewed:

Start here

2 under active exploitation, 0 publicly disclosed before the fix. Everything else in this release can wait behind these.

  • CVE-2026-81963 exploitedWindows Update Stack Elevation of Privilege Vulnerability · CVSS 7.8
  • CVE-2026-85880 exploitedWindows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability · CVSS 7.8

973 shown of 973 · 113 Critical · 438 elevation of privilege · 2 under attack or disclosed9 entries in this release need no action from you: Microsoft has already fixed them service-side. Tick the box above to exclude them.

CVEProductImpactSeverityCVSS
CVE-2026-81963exploitedWindows Update StackWindows Update Stack Elevation of Privilege VulnerabilityElevation of PrivilegeImportantExploitation Detected7.8
CVE-2026-85880exploitedWindows ALPCWindows Advanced Local Procedure Call (ALPC) Elevation of Privilege VulnerabilityElevation of PrivilegeImportantExploitation Detected7.8
CVE-2026-70352no actionAzure AI LanguageAzure AI Language Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A10.0
CVE-2026-83711no actionMicrosoft Azure Active Directory B2CMicrosoft Azure Active Directory B2C Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A10.0
CVE-2026-83941no actionEntra IDEntra ID Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.9
CVE-2026-66302Skype for BusinessSkype for Business Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-69579Windows Message QueuingWindows Message Queuing Remote Code Execution VulnerabilityRemote Code ExecutionCritical9.8
CVE-2026-69590Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-69595Windows Services for NFS ONCRPC XDR DriverWindows Services for NFS ONCRPC XDR Driver Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-69730Windows DNSWindows DNS Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation More Likely9.8
CVE-2026-69769Windows HTTP Print ProviderWindows HTTP Print Provider Remote Code Execution VulnerabilityRemote Code ExecutionCritical9.8
CVE-2026-69829Windows ShellWindows Shell Remote Code Execution VulnerabilityRemote Code ExecutionCritical9.8
CVE-2026-69845Windows DHCP ServerWindows DHCP Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-70296Windows Imaging ComponentWindows Imaging Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-72979Windows DHCP ServerWindows DHCP Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-72982Windows NetlogonWindows Netlogon Remote Code Execution VulnerabilityRemote Code ExecutionCritical9.8
CVE-2026-72983Windows Internet Connection Sharing (ICS)Internet Connection Sharing (ICS) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-73009Windows Secure Socket Tunneling Protocol (SSTP)Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-73010Windows Failover ClusterMicrosoft Failover Cluster Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-77493Microsoft Graphics ComponentWindows Graphics Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-78445Windows Services for NFS ONCRPC XDR DriverWindows Services for NFS ONCRPC XDR Driver Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-78509Microsoft Office OutlookMicrosoft Office Outlook Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-78510Microsoft Office WordMicrosoft Word Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-65669SQL ServerMicrosoft SQL Server Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation Less Likely9.6
CVE-2026-80098no actionCopilot StudioCopilot Studio Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.3
CVE-2026-62916no actionMicrosoft Entra IDMicrosoft Entra ID Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.1
CVE-2026-69854Spring Cloud AzureSpring Cloud Azure Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation More Likely9.0
CVE-2026-65772Microsoft Dynamics 365Microsoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-67631SQL ServerMicrosoft SQL Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-67643SQL ServerMicrosoft SQL Server Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.8
CVE-2026-69285Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69499Windows Imaging ComponentWindows Imaging Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69518Windows Remote DesktopWindows Remote Desktop Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69601Microsoft Windows Media FoundationMicrosoft Windows Media Foundation Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69603Windows Hyper-VWindows Hyper-V Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.8
CVE-2026-69632Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69649Windows Raw Image ExtensionRaw Image Extension Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69676Windows KerberosWindows Kerberos Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation More Likely8.8
CVE-2026-69678Microsoft Office PowerPointMicrosoft Office PowerPoint Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69712Windows Key Distribution CenterWindows Key Distribution Center Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69740Windows HelloWindows Hello Elevation of Privilege VulnerabilityElevation of PrivilegeCritical8.8
CVE-2026-69767Microsoft Office PowerPointMicrosoft Office PowerPoint Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69784Windows HelloWindows Hello Elevation of Privilege VulnerabilityElevation of PrivilegeCritical8.8
CVE-2026-69797Microsoft Office PowerPointMicrosoft Office PowerPoint Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-69860Windows Imaging ComponentWindows Imaging Component Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.8
CVE-2026-70203Windows Media PlayerWindows Media Player Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-70351Microsoft WebP Image ExtensionMicrosoft WebP Image Extension Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.8
CVE-2026-70586Windows PaintWindows Paint Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.8
CVE-2026-72950Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.8
CVE-2026-72959Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-72960Windows Media PlayerWindows Media Player Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.8
CVE-2026-72986Graphic FontsGraphic Fonts Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-73006Microsoft Graphics ComponentDirectWrite Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-73013Windows Imaging ComponentWindows Imaging Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-73018Graphic FontsGraphic Fonts Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-73023Windows Imaging ComponentWindows Imaging Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-77495Windows Imaging ComponentWindows Imaging Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-77504Microsoft Office WordMicrosoft Office Word Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-78439Microsoft Graphics ComponentMicrosoft Office Graphics Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-78505Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8

What this release looks like, before you filter it

Currently loaded: Microsoft’s 2026-Sep release, published , carrying 973 CVE numbers Microsoft assigned itself, of which 964 need something deploying. A further 197 come from Chromium and the open source packages inside Azure Linux, which Microsoft reships under the same release. Those are real, and they are in the table behind a checkbox, but they are not what anybody means by “this month’s Patch Tuesday”.

By severity

  • Important860
  • Critical113

By impact

  • Elevation of Privilege438
  • Remote Code Execution258
  • Information Disclosure173
  • Denial of Service56
  • Security Feature Bypass19
  • Spoofing16
  • Tampering13

Elevation of privilege is the largest class in this release, ahead of remote code execution. That is worth reading twice before triaging by severity: it describes what an attacker does once they are already on the machine, and the only vulnerability Microsoft confirmed as exploited this month is one of them. The reasoning is in the briefing on this release.

Where the numbers come from

Built by script from Microsoft’s machine-readable document for this release, the same one that backs the September 2026 release note. Severity, impact, CVSS, exploitation status and the authority that assigned each number are Microsoft’s own classification, carried through unchanged. Nothing on this page is inferred, and the script that builds it is in the repository so the figures can be reproduced rather than believed.

Corrected on 12 August 2026. This tool first shipped with 438 CVEs for the August release, taken from a spreadsheet export. That export is a rolling thirty-day view rather than a single release, so it carried nineteen entries belonging to July or to old Dynamics re-releases. The correct figure for August was 420. It is recorded here rather than quietly fixed, because it is exactly the mistake the accompanying briefing accuses other people of making.

The whole release is available as JSON at /api/tools/patch-tuesday-2026-09.json, free to use with attribution.

Common questions

›Why do published CVE counts for the same Patch Tuesday disagree?

Because they are counting different things. Microsoft's September 2026 file carries 973 CVE numbers that Microsoft assigned itself, and 9 of them need no action from anybody: service-side fixes to Entra ID, Azure AI Language, Copilot Studio, Power Automate, Cosmos DB and Fabric that Microsoft had already deployed. Exclude those and the total is 964. A further 197 come from Chromium and the Azure Linux packages Microsoft reships, which takes the document to 1,170. All three numbers can be quoted honestly. None is wrong; state which basis you used.

›Should I patch by severity rating?

Not by severity alone. In the September 2026 release both vulnerabilities Microsoft confirms as exploited are rated Important rather than Critical and both score 7.8, because the rating weighs the requirement for local access. Sorting on severity puts them below 113 Critical entries that nobody is exploiting, two of which are rated 10.0 and need no action at all because Microsoft had already fixed them. Severity describes the vulnerability; it does not describe your estate.

›What does customer action required mean?

Microsoft marks entries where the fix is theirs to deploy rather than yours to install, typically in Azure, Teams or Microsoft 365. They still receive a CVE number and still appear in vulnerability reports, which quietly dilutes any remediation percentage that counts them. Use the checkbox above to exclude them when you are measuring patching effort.

›Which release does this cover?

September 2026, published on 8 September 2026. This page carries one release at a time rather than an archive, because the question it answers is about the month you are currently patching. The August 2026 dataset stays reachable at /api/tools/patch-tuesday-2026-08.json, so nothing that linked to it breaks.

When you need more than a tool

vCISO advisory

Embedded security leadership: board reporting, programme direction, and risk decisions taken with accountability and written down.

Read more

Share this tool

Free, no sign-up, and nothing you type leaves your browser.

Related analysis

← All free tools