Where
AND
-Infinity
0

Vendor Risk Score

See how microsoft compares to other vendors in security performance

View Risk Score →

Software

microsoft windows operating system
1622
microsoft windows
1582
microsoft windows server 2016
1458
microsoft windows server 2019
1273
microsoft edge
1184
microsoft edge (chromium-based)
966
microsoft windows server
905
microsoft windows 10
891
microsoft windows server 2022
856
microsoft windows 7
792
microsoft windows server 2012 r2
604
microsoft windows 11
599
microsoft windows server 2012
519
microsoft windows 10 22h2
516
microsoft windows 10 21h2
511
microsoft windows 10 1809
507
microsoft windows server 2025
500
microsoft windows rt
496
microsoft windows 11 24h2
475
microsoft windows server 2022 23h2
464
microsoft windows 10 1607
430
microsoft windows 11 23h2
429
microsoft windows server 2022, 23h2 edition
404
microsoft windows server 2008
387
microsoft windows xp
353
microsoft windows 11 22h2
315
microsoft windows vista
314
microsoft edge beta
286
microsoft windows 11 25h2
266
microsoft internet explorer
263
microsoft windows 10 1507
237
microsoft cbl2 kernel 5.15.186.1-1
234
microsoft windows 8.1
230
microsoft windows server 2008 r2
206
microsoft windows 11 26h1
192
microsoft windows 2000
182
microsoft office
162
microsoft sharepoint enterprise server 2016
155
microsoft windows server 2008 r2 for itanium-based systems
150
microsoft azl3 kernel 6.6.117.1-1
147
microsoft azl3 kernel 6.6.96.2-2
138
microsoft windows nt
129
microsoft windows rt 8.1
123
microsoft azl3 kernel 6.6.92.2-1
122
microsoft windows server 2003
120
microsoft sharepoint server
119
microsoft azl3 kernel 6.6.139.1-1
116
microsoft sharepoint server 2010
113
microsoft 365 apps for enterprise
111
microsoft windows 11 21h2
111
Severity
6.9
Null Pointer Dereference
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure Access server is still able to accept connections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

First published (updated )
Severity
6.9
SSRF
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, isblockedip in ufo/utils/urlsecurity.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4 destinations, allowing an unauthenticated remote attacker who can influence URLs processed by validateurl to bypass the SSRF guard and reach cloud metadata, internal services, or localhost. This issue is fixed in version 3.0.8.

First published (updated )
Severity
6.1
AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:L/E:U/AU:N/R:A/V:C/RE:M/U:Amber

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic.

The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

1 / 2
Source: MITRE
First published (updated )
Severity
4.8
AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent.

The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.

First published (updated )
Severity
5.7
AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could exploit this vulnerability to consume system resources when the restConnector-2.0 feature is enabled.

1 / 2
Source: MITRE
First published (updated )
Severity
5.9
AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.

1 / 3
Source: MITRE
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Microsoft Office Word Information Disclosure Vulnerability

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Microsoft Office Information Disclosure Vulnerability

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
Input Validation
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.5
Infoleak
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.5
SSRF
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

.NET Information Disclosure Vulnerability

1 / 3
Source: Microsoft
First published (updated )
Severity
5.5
Input Validation
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
Input Validation
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.6
Race Condition, Use After Free
AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.5
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.4
XSS
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.5
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C

Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Microsoft Office Graphics Component Information Disclosure Vulnerability

1 / 2
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

1 / 2
Source: Microsoft
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203