Complete feed
Exploited / KEV
Known exploitation or KEV-listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-68820] Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Critical [CVE-2026-58644] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Critical [CVE-2026-55040] Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft SharePoint Server Security Feature Bypass Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
High [CVE-2026-56155] Active Directory Federation Services Elevation of Privilege Vulnerability
Active Directory Federation Services Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
Medium [CVE-2026-56164] Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
High [CVE-2026-45659] Microsoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
High [CVE-2026-42897] Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 14; Microsoft Exchange Server 2019 Cumulative Update 15; Microsoft Exchange Server Subscription Edition RTM.
Critical [CVE-2026-33824] Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32201] Microsoft SharePoint Server Spoofing Vulnerability
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-32202] Windows Shell Spoofing Vulnerability
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 7 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2025 (Server Core installation).
High [CVE-2026-21510] Windows Shell Security Feature Bypass Vulnerability
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
High [CVE-2026-21513] MSHTML Framework Security Feature Bypass Vulnerability
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
High [CVE-2026-21533] Windows Remote Desktop Services Elevation of Privilege Vulnerability
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
High [CVE-2026-21519] Desktop Window Manager Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-21525] Windows Remote Access Connection Manager Denial of Service Vulnerability
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Critical [CVE-2026-20963] Microsoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2026-20805] Desktop Window Manager Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
High [CVE-2025-60710] Host Process for Windows Tasks Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2025; Windows Server 2025 (Server Core installation).
Critical [CVE-2025-53770] Microsoft SharePoint Server Remote Code Execution Vulnerability
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
Medium [CVE-2025-49706] Microsoft SharePoint Server Spoofing Vulnerability
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.