Early access: this site has moved to bugrater.com.

Security releases

Microsoft

August 2026 Early Security Updates

2026-Aug Aug 6, 2026 Source: Vendor

Imported by the Microsoft release catcher from the MSRC CVRF API (2026-Aug, revision 2026-08-06T07:00:00Z). 20 vulnerabilities, 19 of them carrying an acknowledgement. Draft — review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

724 lines
Showing 701–724 of 724 matching · page 15 of 15 · clear filters
CVE-2026-64899 BR2026-0000-009691 unclaimed
Microsoft Office Information Disclosure Vulnerability
Credited as DongJun Kim (smlijun) with UIUC
CVE-2026-64899 BR2026-0000-009692 unclaimed
Microsoft Office Information Disclosure Vulnerability
Credited as Jongseong Kim (nevul37) with UIUC
CVE-2026-58612 BR2026-0000-010040 unclaimed
PowerShell Information Disclosure Vulnerability
Credited as Theodor N. Engøy
CVE-2026-62815 BR2026-0000-010041 unclaimed
Microsoft QUIC Remote Code Execution Vulnerability
Credited as Damian Regulski
CVE-2026-62815 BR2026-0000-010042 unclaimed
Microsoft QUIC Remote Code Execution Vulnerability
Credited as Quac Tran
CVE-2026-68821 BR2026-0000-010043 unclaimed
Windows Package Manager Elevation of Privilege Vulnerability
Credited as Bilal Teke
CVE-2026-70105 BR2026-0000-010044 unclaimed
Microsoft Word Information Disclosure Vulnerability
Credited as Haein Lee with KAIST Hacking Lab
CVE-2026-62747 BR2026-0000-011770 unclaimed
Windows Device Association Service Elevation of Privilege Vulnerability
Credited as haowei yan
CVE-2026-62747 BR2026-0000-011771 unclaimed
Windows Device Association Service Elevation of Privilege Vulnerability
Credited as xiaozun tang
CVE-2026-62693 BR2026-0000-011871 unclaimed
Windows MIDI Service Module Elevation of Privileges Vulnerability
Credited as h4urek
CVE-2026-62693 BR2026-0000-011872 unclaimed
Windows MIDI Service Module Elevation of Privileges Vulnerability
Credited as Bocheng Xiang with secsys lab
CVE-2026-61349 BR2026-0000-012128 unclaimed
Windows Work Folder Service Elevation of Privilege Vulnerability
Credited as AIフィジカルインターフェイス二号機
CVE-2026-65776 BR2026-0000-012129 unclaimed
Windows Win32k Elevation of Privilege Vulnerability
Credited as grass341 with Viettel Cyber Security
CVE-2026-62717 BR2026-0000-013364 unclaimed
Windows Message Queuing Elevation of Privilege Vulnerability
Credited as Thunder_J
CVE-2026-62753 BR2026-0000-013365 unclaimed
Windows HTTP.sys Elevation of Privilege Vulnerability
Credited as Thanatos Tian (HKPolyU) with https://diffract-ai.com/
CVE-2026-62772 BR2026-0000-013366 unclaimed
Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability
Credited as Kentaro Kawane with GMO Cybersecurity by Ierae, Inc.
CVE-2026-63508 BR2026-0000-013367 unclaimed
Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
Credited as Michal Kamensky with Microsoft
CVE-2026-65775 BR2026-0000-013368 unclaimed
Windows Win32k Elevation of Privilege Vulnerability
Credited as pwn2addr
CVE-2026-62819 BR2026-0000-014361 unclaimed
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Credited as Aobo Wang
CVE-2026-66805 BR2026-0000-014362 unclaimed
Microsoft SharePoint Server Remote Code Execution Vulnerability
Credited as Genwei Jiang with Google Cloud, FLARE OTF
CVE-2026-62871 BR2026-0000-014503 unclaimed
.NET Elevation of Privilege Vulnerability
Credited as nono
CVE-2026-63516 BR2026-0000-014504 unclaimed
Microsoft SharePoint Server Spoofing Vulnerability
Credited as Thanatos Tian (HKPolyU)
CVE-2026-63516 BR2026-0000-014505 unclaimed
Microsoft SharePoint Server Spoofing Vulnerability
Credited as npc0vo with Diffract
CVE-2026-68798 BR2026-0000-014506 unclaimed
Microsoft Excel Remote Code Execution Vulnerability
Credited as Jongseong Kim (nevul37), UIUC