Microsoft Security Response Center, Security Update Guide
msrc-update-guide · A · active
https://msrc.microsoft.com/update-guide
Added 2026-09-29: Microsoft's own per-CVE release data with the exploited / publicly-disclosed flags, the first-party primary for every Patch Tuesday and out-of-band Microsoft fix (msrc-blog is the blog only and carries neither). RECIPE: `fetch_source.py msrc recent N` (newest CVEs with exploitation flags; returned 2026-09 CVEs dated 09-29 at probe), then `msrc cve <CVE>` or `msrc release <tag>` for the CVRF detail; cite the https://msrc.microsoft.com/update-guide/vulnerability/<CVE> page. (2026-09-29 operator-directed setup review) | 2026-09-30: health_cmd msrc recent 10: the update-guide URL is a JS app that the content check reads as a shell, while the `msrc recent` recipe the note names returns dated CVEs (newest release date 2026-09-30 at probe). (2026-09-30T0634Z-audit) | 2026-10-02 (2026-10-02T0404Z-intel): `msrc recent N` interleaves third-party Azure-Linux and Chromium-for-Edge CVEs with first-party ones; filter on the exploited/publiclyDisclosed flags and on non-third-party titles (200 rows reached back only to 2026-09-28). | 2026-10-06 (S1, not re-verified by the main agent): `python3 tools/fetch_source.py msrc cvrf <release-id>` (e.g. 2026-Oct) returns Remediations with KB numbers and FixedBuild values; `msrc recent N` and `msrc cve` give no KB list.
Cited in 34 entries
Citation cadence
Citation days per ISO week (21 weeks of coverage span, total 27).
- CVE-2026-65660, Microsoft SharePoint: a SafeControls parser-desync lets an authenticated attacker forge a second Register directive and reach RCE via in-memory XAML deserialization, now confirmed exploited (CVSS 8.8)2026-09-26
- CVE-2026-66804, Windows Cross Device Service: a dangling COM registration reaches SYSTEM privilege escalation, and Google Project Zero publishes a general method to hunt for others2026-09-22
- September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)2026-09-09
- CVE-2026-62911, Microsoft Exchange Server MRSProxy: a missing channel-binding check lets a relayed Negotiate authentication take over every mailbox, public exploit code now live sixteen days after the patch2026-08-29
- CVE-2026-69836, Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later2026-08-23
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 20252026-08-12
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers2026-08-12
- NatJack, sharing a NAT table is a trust relationship nobody declared: five named primitives against NAT state, of which only the downstream TCP hijack got a CVE on each platform2026-08-10
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual exploitation of Citrix NetScaler (CVE-2026-3055) and Marimo notebooks, not the agent2026-07-31
- LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems2026-07-29
- CVE-2026-54121, Windows Server AD CS 'Certighost': low-priv domain user forges a DC certificate to DCSync, full PoC public (CVSS 8.8)2026-07-25
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series2026-07-09
- CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed2026-07-02
- Nightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch2026-06-19
- Varonis "SearchLeak" (CVE-2026-42824): one-click M365 Copilot data exfiltration, now patched2026-06-16
- June 2026 Patch Tuesday: four CVSS ≥ 9.1 criticals, Windows kernel TCP/IP RCE, Nuance PowerScribe, Azure Stack Edge, Exchange Online2026-06-12
- CVE-2026-47344 et al. TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)2026-06-10
- CVE-2026-47291, Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)2026-06-10
- Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop2026-05-30
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain2026-05-29
- Keycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)2026-05-21
- CVE-2026-42822, Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, "Exploitation More Likely"2026-05-21
- vm2 Node.js sandbox, 12 critical CVEs (CVE-2026-43997 / 43999 / 44005 / 44006 / 44008 / 44009 et al.), sandbox escape to host RCE, upgrade to ≥ 3.11.42026-05-20
- CVE-2026-45584, Microsoft Defender Engine heap-buffer-overflow RCE over network2026-05-20
- CVE-2026-41091, Microsoft Defender Engine link-following EoP, actively exploited2026-05-20
- CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com2026-05-18
- Exchange CVE-2026-42897, Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation2026-05-17
- Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch2026-05-16
- CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch2026-05-16
- AMD-SB-7052 / CVE-2025-54518, AMD Zen 2 µop-cache corruption / SoC isolation failure: local privilege escalation (CVSS 7.3), microcode mitigation in May 2026 Windows update and Xen XSA-4902026-05-16
- Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed2026-05-15
- CVE-2026-41089 / CVE-2026-41096 / CVE-2026-41103 / CVE-2026-42898; Microsoft May 2026 Patch Tuesday (120+ CVEs, no zero-days)2026-05-13
- CVE-2026-32202 in Windows Shell: an incomplete fix for an APT28-exploited LNK flaw leaks NTLM hashes when a folder is opened, exploited and re-released in July (CVSS 4.3)2026-05-08