Multiple vulnerabilities in Microsoft products (August 12, 2026)
Multiple vulnerabilities have been discovered in Microsoft products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities across Microsoft products enable remote code execution, privilege escalation, and denial of service.
- Who is affected
- Deployments of Microsoft products affected by the listed CVEs.
- Urgency
- Highly urgent; multiple RCE vulnerabilities across the Microsoft product portfolio warrant immediate patching.
- Action
- Apply Microsoft August 2026 security updates across all affected products.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1004/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-591190.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-649220.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-692780.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657670.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628970.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-629121.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628270.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648970.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-472850.89% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-635120.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Microsoft Dynamics: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Microsoft Exchange Server: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Microsoft Windows Package Manager: Vulnerability enables Privilege Escalationcert-bund
- high[NEW] [high] Microsoft Power BI: Vulnerability enables Code Executioncert-bund
- high[NEW] [high] Microsoft Azure and Entra ID: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Microsoft Defender for Endpoint: Vulnerability enables Information Disclosurecert-bund
- unknownNCSC-2026-0289 [1.00] [M/H] Vulnerabilities fixed in Microsoft Exchange Serverncsc-nl
- unknownNCSC-2026-0287 [1.00] [M/H] Vulnerabilities fixed in Microsoft Azurencsc-nl
- unknownMultiple vulnerabilities in Microsoft .Net (August 12, 2026)cert-fr-avis
- unknownNCSC-2026-0290 [1.00] [M/H] Vulnerability patched in Microsoft Power BI serverncsc-nl
- unknownNCSC-2026-0286 [1.00] [M/H] Vulnerabilities patched in Microsoft Officencsc-nl
Recent advisories for Microsoft products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilitiescert-bund · 2026-08-14
- high[NEW] [high] Microsoft Office Products: Multiple Vulnerabilitiescert-bund · 2026-08-13
- critical[NEW] [critical] Microsoft Office products: Multiple vulnerabilitiescert-bund · 2026-08-13
- critical[NEW] [critical] Microsoft Windows products: Multiple vulnerabilitiescert-bund · 2026-08-05
- unknownMultiple vulnerabilities in Microsoft products (July 17, 2026)cert-fr-avis · 2026-07-17
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis · 2026-07-15
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14