

Microsoft's monthly release, filterable
Patch Tuesday browser
Filter every CVE in Microsoft's latest Patch Tuesday by product, severity and impact. Search by CVE number, export what you filtered as CSV.
Microsoft publishes several hundred CVEs on the second Tuesday of each month, as a spreadsheet and a release note. Neither answers the question people actually arrive with, which is never “show me four hundred rows”. It is “what critical remote code execution landed on SharePoint”, or “is this CVE in this month”. This filters rather than prints, and the counts recompute as you filter, because the count is usually the answer.
Nothing leaves your browser: Everything happens in your browser against data already loaded with the page. No search term, filter or export leaves your machine, and this page is served with a Content Security Policy that forbids it from making any outbound request at all.
Start here
1 under active exploitation, 2 publicly disclosed before the fix. Everything else in this release can wait behind these.
- CVE-2026-62832 publicly disclosedWindows User Profile Service Elevation of Privilege Vulnerability · CVSS 7.8
- CVE-2026-68820 exploitedWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability · CVSS 7
- CVE-2026-72971 publicly disclosedWindows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability · CVSS 5.5
420 shown of 420 · 62 Critical · 176 elevation of privilege · 3 under attack or disclosed20 entries in this release need no action from you: Microsoft has already fixed them service-side. Tick the box above to exclude them.
| CVE | Product | Impact | Severity | CVSS |
|---|---|---|---|---|
| CVE-2026-68820exploited | Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | ImportantExploitation Detected | 7.0 |
| CVE-2026-62832disclosed | Windows User Profile ServiceWindows User Profile Service Elevation of Privilege Vulnerability | Elevation of Privilege | ImportantExploitation More Likely | 7.8 |
| CVE-2026-72971disclosed | Windows Container Isolation FS Filter Driver (unionfs.sys)Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability | Tampering | Important | 5.5 |
| CVE-2026-56162no action | Azure SQL DatabaseAzure SQL Database Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 10.0 |
| CVE-2026-63508no action | Microsoft Planetary Computer ProMicrosoft Planetary Computer Pro Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 10.0 |
| CVE-2026-65667no action | Microsoft TeamsMicrosoft Teams Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 10.0 |
| CVE-2026-50481no action | Azure Active DirectoryAzure Active Directory Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.9 |
| CVE-2026-50515no action | Azure Service BusAzure Service Bus Remote Code Execution Vulnerability | Remote Code Execution | CriticalN/A | 9.9 |
| CVE-2026-59115no action | Microsoft Entra Provisioning Service (SyncFabric)Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.9 |
| CVE-2026-62830no action | Azure SRE AgentAzure SRE Agent Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation Less Likely | 9.9 |
| CVE-2026-62815 | Microsoft QUICMicrosoft QUIC Remote Code Execution Vulnerability | Remote Code Execution | CriticalN/A | 9.8 |
| CVE-2026-62873no action | Microsoft 365 Admin CenterMicrosoft 365 Admin Center Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.8 |
| CVE-2026-62878 | Windows DNSWindows DNS Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 9.8 |
| CVE-2026-62893 | Windows Deployment ServicesWindows Deployment Services TFTP Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation More Likely | 9.8 |
| CVE-2026-65791 | Windows iSCSI Target ServiceWindows iSCSI Target Service Remote Code Execution Vulnerability | Remote Code Execution | Critical | 9.8 |
| CVE-2026-56161no action | Azure Logic AppsAzure Logic Apps Information Disclosure Vulnerability | Information Disclosure | CriticalN/A | 9.6 |
| CVE-2026-62896no action | Microsoft TeamsMicrosoft Teams Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.6 |
| CVE-2026-70332no action | Microsoft Office SharePointMicrosoft Office SharePoint Spoofing Vulnerability | Spoofing | CriticalN/A | 9.6 |
| CVE-2026-50516no action | Microsoft Azure Kubernetes ServiceMicrosoft Azure Kubernetes Service Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation Less Likely | 9.4 |
| CVE-2026-59118no action | Copilot CoworkCopilot Cowork Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 9.3 |
| CVE-2026-68823no action | Azure Confidential LedgerAzure Confidential Ledger Remote Code Execution Vulnerability | Remote Code Execution | CriticalN/A | 9.1 |
| CVE-2026-49163no action | Application Insights ProfilerApplication Insights Profiler Elevation of Privilege Vulnerability | Elevation of Privilege | Critical | 8.8 |
| CVE-2026-62816 | Reliable Multicast Transport Driver (RMCAST)Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-62817 | Windows DNSWindows DNS Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-62818 | Active Directory Certificate Services (AD CS)Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-62822 | Windows GDI+Windows GDI+ Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-62823 | Windows DHCP ServerWindows DHCP Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation More Likely | 8.8 |
| CVE-2026-62824 | Remote Desktop ClientRemote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-62827 | Microsoft Office SharePointMicrosoft SharePoint Server Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-62869no action | Azure Entra IDAzure Entra ID Spoofing Vulnerability | Spoofing | CriticalN/A | 8.8 |
| CVE-2026-64921 | Microsoft Office SharePointMicrosoft SharePoint Server Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation Less Likely | 8.8 |
| CVE-2026-65665 | Microsoft Office SharePointMicrosoft SharePoint Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation More Likely | 8.8 |
| CVE-2026-65668no action | Microsoft Purview eDiscoveryMicrosoft Purview eDiscovery Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 8.8 |
| CVE-2026-62836no action | Azure SQL Managed InstanceAzure SQL Managed Instance Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 8.7 |
| CVE-2026-70130 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.4 |
| CVE-2026-62819 | Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.1 |
| CVE-2026-62820 | Windows DNSWindows DNS Server Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.1 |
| CVE-2026-62889 | Windows Secure Socket Tunneling Protocol (SSTP)Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.1 |
| CVE-2026-65789 | Windows DNSWindows DNS Server Remote Code Execution Vulnerability | Remote Code Execution | Critical | 8.1 |
| CVE-2026-66802 | Microsoft Azure Attestation service and Device Health Attestation ServiceWindows Device Health Attestation (DHA) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.1 |
| CVE-2026-71331 | Microsoft Azure Attestation service and Device Health Attestation ServiceWindows Device Health Attestation (DHA) Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 8.1 |
| CVE-2026-62911 | Microsoft Exchange ServerMicrosoft Exchange Server Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation Less Likely | 8.0 |
| CVE-2026-62890 | Windows GDI+Windows GDI+ Elevation of Privilege Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-63513 | Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-63515 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-63518 | Microsoft Office WordMicrosoft Office Word Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-63519 | Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-63522no action | Azure SQL DatabaseAzure SQL Database Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalN/A | 7.8 |
| CVE-2026-63525 | Microsoft Office WordMicrosoft Office Word Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-63526 | Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-63532 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-64898 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-64903 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-64907 | Microsoft Office WordMicrosoft Office Word Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-64909 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-64910 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-64911 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-65657 | Microsoft OfficeMicrosoft Office Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-65664 | Microsoft OfficeMicrosoft Office Graphics Component Remote Code Execution Vulnerability | Remote Code Execution | CriticalExploitation Less Likely | 7.8 |
| CVE-2026-66799 | Windows Key GuardWindows Key Guard Elevation of Privilege Vulnerability | Elevation of Privilege | CriticalExploitation Less Likely | 7.8 |
What this release looks like, before you filter it
Currently loaded: Microsoft’s 2026-Aug release, published , carrying 420 CVE numbers Microsoft assigned itself, of which 400 need something deploying. A further 370come from Chromium and the open source packages inside Azure Linux, which Microsoft reships under the same release. Those are real, and they are in the table behind a checkbox, but they are not what anybody means by “this month’s Patch Tuesday”.
By severity
- Important356
- Critical62
- Unknown1
- Moderate1
By impact
- Elevation of Privilege176
- Remote Code Execution111
- Information Disclosure85
- Spoofing20
- Denial of Service12
- Security Feature Bypass11
- Tampering4
- Unknown1
Elevation of privilege is the largest class in this release, ahead of remote code execution. That is worth reading twice before triaging by severity: it describes what an attacker does once they are already on the machine, and the only vulnerability Microsoft confirmed as exploited this month is one of them. The reasoning is in the briefing on this release.
Where the numbers come from
Built by script from Microsoft’s machine-readable document for this release, the same one that backs the August 2026 release note. Severity, impact, CVSS, exploitation status and the authority that assigned each number are Microsoft’s own classification, carried through unchanged. Nothing on this page is inferred, and the script that builds it is in the repository so the figures can be reproduced rather than believed.
Corrected on 12 August 2026. This tool first shipped with 438 CVEs, taken from a spreadsheet export. That export is a rolling thirty-day view rather than a single release, so it carried nineteen entries belonging to July or to old Dynamics re-releases. The figure for the August release is 420. The correction is small and it is exactly the mistake the accompanying briefing accuses other people of making, which is why it is written here rather than quietly fixed.
The whole release is available as JSON at /api/tools/patch-tuesday-2026-08.json, free to use with attribution.
Common questions
›Why do published CVE counts for the same Patch Tuesday disagree?
Because they are counting different things. Microsoft's August 2026 file carries 438 unique CVE numbers, and 20 of them need no action from anybody: they are service-side fixes to Azure, Teams and Microsoft 365 that Microsoft has already deployed. Exclude those and the total is 418. Published figures for this release ranged from 394 to 421 depending on whether each outlet counted the cloud entries, the Edge entry, or only items with a downloadable update. None is wrong; state which basis you used.
›Should I patch by severity rating?
Not by severity alone. In the August 2026 release the only vulnerability Microsoft confirmed as exploited was rated Important rather than Critical, because the rating weighs the requirement for local access. Sorting on severity puts it below 64 Critical entries that nobody is exploiting. Severity describes the vulnerability; it does not describe your estate.
›What does customer action required mean?
Microsoft marks entries where the fix is theirs to deploy rather than yours to install, typically in Azure, Teams or Microsoft 365. They still receive a CVE number and still appear in vulnerability reports, which quietly dilutes any remediation percentage that counts them. Use the checkbox above to exclude them when you are measuring patching effort.
›Which release does this cover?
August 2026, published on 11 August 2026. This page carries one release at a time rather than an archive, because the question it answers is about the month you are currently patching.
When you need more than a tool
vCISO Advisory
Embedded security leadership one to three days a week: board reporting, programme direction, and decisions taken with accountability, without a full-time hire.
Discuss vCISO supportRelated analysis
