P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Microsoft's monthly release, filterable

Patch Tuesday browser

Filter every CVE in Microsoft's latest Patch Tuesday by product, severity and impact. Search by CVE number, export what you filtered as CSV.

Microsoft publishes several hundred CVEs on the second Tuesday of each month, as a spreadsheet and a release note. Neither answers the question people actually arrive with, which is never “show me four hundred rows”. It is “what critical remote code execution landed on SharePoint”, or “is this CVE in this month”. This filters rather than prints, and the counts recompute as you filter, because the count is usually the answer.

Nothing leaves your browser: Everything happens in your browser against data already loaded with the page. No search term, filter or export leaves your machine, and this page is served with a Content Security Policy that forbids it from making any outbound request at all.

Last reviewed:

Start here

1 under active exploitation, 2 publicly disclosed before the fix. Everything else in this release can wait behind these.

  • CVE-2026-62832 publicly disclosedWindows User Profile Service Elevation of Privilege Vulnerability · CVSS 7.8
  • CVE-2026-68820 exploitedWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability · CVSS 7
  • CVE-2026-72971 publicly disclosedWindows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability · CVSS 5.5

420 shown of 420 · 62 Critical · 176 elevation of privilege · 3 under attack or disclosed20 entries in this release need no action from you: Microsoft has already fixed them service-side. Tick the box above to exclude them.

CVEProductImpactSeverityCVSS
CVE-2026-68820exploitedWindows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityElevation of PrivilegeImportantExploitation Detected7.0
CVE-2026-62832disclosedWindows User Profile ServiceWindows User Profile Service Elevation of Privilege VulnerabilityElevation of PrivilegeImportantExploitation More Likely7.8
CVE-2026-72971disclosedWindows Container Isolation FS Filter Driver (unionfs.sys)Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering VulnerabilityTamperingImportant5.5
CVE-2026-56162no actionAzure SQL DatabaseAzure SQL Database Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A10.0
CVE-2026-63508no actionMicrosoft Planetary Computer ProMicrosoft Planetary Computer Pro Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A10.0
CVE-2026-65667no actionMicrosoft TeamsMicrosoft Teams Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A10.0
CVE-2026-50481no actionAzure Active DirectoryAzure Active Directory Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.9
CVE-2026-50515no actionAzure Service BusAzure Service Bus Remote Code Execution VulnerabilityRemote Code ExecutionCriticalN/A9.9
CVE-2026-59115no actionMicrosoft Entra Provisioning Service (SyncFabric)Microsoft Entra Provisioning Service Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.9
CVE-2026-62830no actionAzure SRE AgentAzure SRE Agent Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation Less Likely9.9
CVE-2026-62815Microsoft QUICMicrosoft QUIC Remote Code Execution VulnerabilityRemote Code ExecutionCriticalN/A9.8
CVE-2026-62873no actionMicrosoft 365 Admin CenterMicrosoft 365 Admin Center Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.8
CVE-2026-62878Windows DNSWindows DNS Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely9.8
CVE-2026-62893Windows Deployment ServicesWindows Deployment Services TFTP Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation More Likely9.8
CVE-2026-65791Windows iSCSI Target ServiceWindows iSCSI Target Service Remote Code Execution VulnerabilityRemote Code ExecutionCritical9.8
CVE-2026-56161no actionAzure Logic AppsAzure Logic Apps Information Disclosure VulnerabilityInformation DisclosureCriticalN/A9.6
CVE-2026-62896no actionMicrosoft TeamsMicrosoft Teams Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.6
CVE-2026-70332no actionMicrosoft Office SharePointMicrosoft Office SharePoint Spoofing VulnerabilitySpoofingCriticalN/A9.6
CVE-2026-50516no actionMicrosoft Azure Kubernetes ServiceMicrosoft Azure Kubernetes Service Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation Less Likely9.4
CVE-2026-59118no actionCopilot CoworkCopilot Cowork Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A9.3
CVE-2026-68823no actionAzure Confidential LedgerAzure Confidential Ledger Remote Code Execution VulnerabilityRemote Code ExecutionCriticalN/A9.1
CVE-2026-49163no actionApplication Insights ProfilerApplication Insights Profiler Elevation of Privilege VulnerabilityElevation of PrivilegeCritical8.8
CVE-2026-62816Reliable Multicast Transport Driver (RMCAST)Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-62817Windows DNSWindows DNS Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-62818Active Directory Certificate Services (AD CS)Windows Active Directory Certificate Services (AD CS) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-62822Windows GDI+Windows GDI+ Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-62823Windows DHCP ServerWindows DHCP Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation More Likely8.8
CVE-2026-62824Remote Desktop ClientRemote Desktop Client Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.8
CVE-2026-62827Microsoft Office SharePointMicrosoft SharePoint Server Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation Less Likely8.8
CVE-2026-62869no actionAzure Entra IDAzure Entra ID Spoofing VulnerabilitySpoofingCriticalN/A8.8
CVE-2026-64921Microsoft Office SharePointMicrosoft SharePoint Server Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation Less Likely8.8
CVE-2026-65665Microsoft Office SharePointMicrosoft SharePoint Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation More Likely8.8
CVE-2026-65668no actionMicrosoft Purview eDiscoveryMicrosoft Purview eDiscovery Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A8.8
CVE-2026-62836no actionAzure SQL Managed InstanceAzure SQL Managed Instance Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A8.7
CVE-2026-70130Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.4
CVE-2026-62819Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.1
CVE-2026-62820Windows DNSWindows DNS Server Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.1
CVE-2026-62889Windows Secure Socket Tunneling Protocol (SSTP)Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.1
CVE-2026-65789Windows DNSWindows DNS Server Remote Code Execution VulnerabilityRemote Code ExecutionCritical8.1
CVE-2026-66802Microsoft Azure Attestation service and Device Health Attestation ServiceWindows Device Health Attestation (DHA) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.1
CVE-2026-71331Microsoft Azure Attestation service and Device Health Attestation ServiceWindows Device Health Attestation (DHA) Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely8.1
CVE-2026-62911Microsoft Exchange ServerMicrosoft Exchange Server Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation Less Likely8.0
CVE-2026-62890Windows GDI+Windows GDI+ Elevation of Privilege VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-63513Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-63515Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-63518Microsoft Office WordMicrosoft Office Word Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-63519Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-63522no actionAzure SQL DatabaseAzure SQL Database Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalN/A7.8
CVE-2026-63525Microsoft Office WordMicrosoft Office Word Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-63526Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-63532Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-64898Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-64903Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-64907Microsoft Office WordMicrosoft Office Word Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-64909Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-64910Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-64911Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-65657Microsoft OfficeMicrosoft Office Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-65664Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution VulnerabilityRemote Code ExecutionCriticalExploitation Less Likely7.8
CVE-2026-66799Windows Key GuardWindows Key Guard Elevation of Privilege VulnerabilityElevation of PrivilegeCriticalExploitation Less Likely7.8

What this release looks like, before you filter it

Currently loaded: Microsoft’s 2026-Aug release, published , carrying 420 CVE numbers Microsoft assigned itself, of which 400 need something deploying. A further 370come from Chromium and the open source packages inside Azure Linux, which Microsoft reships under the same release. Those are real, and they are in the table behind a checkbox, but they are not what anybody means by “this month’s Patch Tuesday”.

By severity

  • Important356
  • Critical62
  • Unknown1
  • Moderate1

By impact

  • Elevation of Privilege176
  • Remote Code Execution111
  • Information Disclosure85
  • Spoofing20
  • Denial of Service12
  • Security Feature Bypass11
  • Tampering4
  • Unknown1

Elevation of privilege is the largest class in this release, ahead of remote code execution. That is worth reading twice before triaging by severity: it describes what an attacker does once they are already on the machine, and the only vulnerability Microsoft confirmed as exploited this month is one of them. The reasoning is in the briefing on this release.

Where the numbers come from

Built by script from Microsoft’s machine-readable document for this release, the same one that backs the August 2026 release note. Severity, impact, CVSS, exploitation status and the authority that assigned each number are Microsoft’s own classification, carried through unchanged. Nothing on this page is inferred, and the script that builds it is in the repository so the figures can be reproduced rather than believed.

Corrected on 12 August 2026. This tool first shipped with 438 CVEs, taken from a spreadsheet export. That export is a rolling thirty-day view rather than a single release, so it carried nineteen entries belonging to July or to old Dynamics re-releases. The figure for the August release is 420. The correction is small and it is exactly the mistake the accompanying briefing accuses other people of making, which is why it is written here rather than quietly fixed.

The whole release is available as JSON at /api/tools/patch-tuesday-2026-08.json, free to use with attribution.

Common questions

Why do published CVE counts for the same Patch Tuesday disagree?

Because they are counting different things. Microsoft's August 2026 file carries 438 unique CVE numbers, and 20 of them need no action from anybody: they are service-side fixes to Azure, Teams and Microsoft 365 that Microsoft has already deployed. Exclude those and the total is 418. Published figures for this release ranged from 394 to 421 depending on whether each outlet counted the cloud entries, the Edge entry, or only items with a downloadable update. None is wrong; state which basis you used.

Should I patch by severity rating?

Not by severity alone. In the August 2026 release the only vulnerability Microsoft confirmed as exploited was rated Important rather than Critical, because the rating weighs the requirement for local access. Sorting on severity puts it below 64 Critical entries that nobody is exploiting. Severity describes the vulnerability; it does not describe your estate.

What does customer action required mean?

Microsoft marks entries where the fix is theirs to deploy rather than yours to install, typically in Azure, Teams or Microsoft 365. They still receive a CVE number and still appear in vulnerability reports, which quietly dilutes any remediation percentage that counts them. Use the checkbox above to exclude them when you are measuring patching effort.

Which release does this cover?

August 2026, published on 11 August 2026. This page carries one release at a time rather than an archive, because the question it answers is about the month you are currently patching.

When you need more than a tool

vCISO Advisory

Embedded security leadership one to three days a week: board reporting, programme direction, and decisions taken with accountability, without a full-time hire.

Discuss vCISO support

Share this tool

Free, no sign-up, and nothing you type leaves your browser.

Related analysis

← All free tools