Microsoft vulnerabilities
1545 CVEs tracked
Microsoft appears in this reporting cycle amid massive service disruptions and actively exploited critical vulnerabilities. Operational incidents include a widespread Microsoft 365 and Teams outage and an Exchange Online mailbox quarantine issue. Defenders must prioritize the SharePoint deserialization vulnerabilities added to the KEV list (CVE-2026-50522, CVE-2026-58644), along with the required patch application for older actively exploited CVEs like CVE-2019-0604, CVE-2023-29357, and CVE-2024-38094. Attention should also be given to novel attack surfaces including flaws in Passkey implementation, an Azure DevOps MCP flaw allowing AI agent hijacking, and the HollowGraph malware's unusual C2 tactic of leveraging Microsoft 365 calendar events.
Azərbaycanca: Microsoft hesabat dövründə genişmiqyaslı xidmət pozuntuları və aktiv istismar edilən kritik zəifliklər kontekstində görünür. Microsoft 365 və Teams üzrə kütləvi kəsinti və Exchange Online karantin problemi kimi əməliyyat hadisələri qeydə alınıb. Əsas diqqət KEV siyahısına daxil edilmiş SharePoint deserializasiya zəifliklərinə (CVE-2026-50522, CVE-2026-58644) yönəlməlidir; bunlarla yanaşı, köhnə CVE-lər (CVE-2019-0604, CVE-2023-29357, CVE-2024-38094) üçün aktual patch tətbiqi tələb olunur. Müdafiəçilər həmçinin Passkey tətbiqindəki qüsurlar, Azure DevOps MCP boşluğu və HollowGraph zərərli proqramının Microsoft 365 təqvimi ilə əlaqəli qeyri-adi C2 taktikası kimi yeni hücum səthlərini dəyərləndirməlidirlər.
This vendor's CVEs60
- CVE-2026-68820KEVEPSS 6%
- CVE-2026-65400KEVEPSS 10%
- CVE-2026-58644KEVEPSS 16%
- CVE-2026-56164KEVEPSS 27%
- CVE-2026-56155KEVEPSS 0.35%
- CVE-2026-55040KEVEPSS 40%
- CVE-2026-50522KEVEPSS 85%
- CVE-2026-45659KEVEPSS 76%
- CVE-2026-41091KEVEPSS 8%
- CVE-2026-33824KEVEPSS 73%
- CVE-2026-32201KEVEPSS 43%
- CVE-2026-21533KEVEPSS 4%
- CVE-2026-21525KEVEPSS 5%
- CVE-2026-21519KEVEPSS 2%
- CVE-2026-21514KEVEPSS 2%
- CVE-2026-21513KEVEPSS 15%
- CVE-2026-21510KEVEPSS 26%
- CVE-2026-21509KEVEPSS 73%
- CVE-2026-20963KEVEPSS 32%
- CVE-2026-11645KEVEPSS 2%
- CVE-2025-53770KEVEPSS 100%
- CVE-2025-49706KEVEPSS 99%
- CVE-2025-49704KEVEPSS 100%
- CVE-2024-38094KEVEPSS 51%
- CVE-2023-29357KEVEPSS 100%
- CVE-2023-24955KEVEPSS 85%
- CVE-2020-1147KEVEPSS 94%
- CVE-2019-0604KEVEPSS 100%
- CVE-2026-73297EPSS 2%
- CVE-2026-73296EPSS 3%
- CVE-2026-72971EPSS 0.47%
- CVE-2026-71331EPSS 0.45%
- CVE-2026-70355EPSS 0.46%
- CVE-2026-70354EPSS 0.29%
- CVE-2026-70348EPSS 0.43%
- CVE-2026-70347EPSS 0.31%
- CVE-2026-70346EPSS 0.31%
- CVE-2026-70345EPSS 0.24%
- CVE-2026-70344EPSS 0.31%
- CVE-2026-70340EPSS 0.60%
- CVE-2026-70338EPSS 0.31%
- CVE-2026-70337EPSS 0.80%
- CVE-2026-70336EPSS 0.61%
- CVE-2026-70335EPSS 0.42%
- CVE-2026-70332EPSS 0.63%
- CVE-2026-70330EPSS 0.32%
- CVE-2026-70329EPSS 0.67%
- CVE-2026-70328EPSS 0.85%
- CVE-2026-70327EPSS 0.85%
- CVE-2026-70326EPSS 0.59%
- CVE-2026-70325EPSS 0.38%
- CVE-2026-70324EPSS 0.70%
- CVE-2026-70323EPSS 0.38%
- CVE-2026-70322EPSS 0.38%
- CVE-2026-70321EPSS 1%
- CVE-2026-70320EPSS 0.38%
- CVE-2026-70319EPSS 0.38%
- CVE-2026-70318EPSS 0.36%
- CVE-2026-70317EPSS 0.36%
- CVE-2026-70316EPSS 0.38%
Showing the top 60 of 1545 — known-exploited and newest first.
This hub is built from skopnix's own reporting on Microsoft: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.