[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Exchange, Microsoft Windows 11, Microsoft Windows Server 2025 and Microsoft Windows to execute arbitrary code, to increase privileges, to conduct a denial of service attack, to disclose information, to manipulate files, to conduct a cross-site scripting attack, and to bypass security measures.
CSIRTS triage
- What
- Multiple vulnerabilities across Windows and Exchange products enable remote code execution, privilege escalation, denial of service, information disclosure, and security bypass.
- Who is affected
- All organizations running Microsoft Windows Server 2012 through 2025, Windows 10 and 11, and Microsoft Exchange.
- Urgency
- Critical; multiple vectors for remote code execution and privilege escalation with no exploitation barriers reported.
- Action
- Apply all available Microsoft security updates immediately for the affected Windows and Exchange versions.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2756
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-628070.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627540.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627500.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627450.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627420.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627350.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627530.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627400.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627550.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627460.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windowsncsc-nl
- mediumCVE-2026-65662: Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locall…nvd
- highCVE-2026-62908: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd
- criticalCVE-2026-62893: Use after free in Windows Deployment Services allows an unauthorized attacker to execute code …nvd
- highCVE-2026-62890: Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code local…nvd
- highCVE-2026-62889: Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker…nvd
- criticalCVE-2026-62878: Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code ove…nvd
- highCVE-2026-62877: Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privile…nvd
- highCVE-2026-62876: Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges local…nvd
- highCVE-2026-62819: Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to g…nvd
- highCVE-2026-62818: Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker …nvd
- highCVE-2026-62816: Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthori…nvd
Recent advisories for Microsoft Windows Products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEW] [critical] Microsoft Windows products: Multiple vulnerabilitiescert-bund · 2026-08-05
- critical[UPDATE] [critical] Microsoft Windows products: Multiple vulnerabilitiescert-bund · 2026-07-09
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17