This release consists of 663 Microsoft
CVEs:
|
Product Family |
Updates per Product/Version |
Vulnerabilities Addressed |
Distinct Updates |
Type of Update |
|
Azure |
1 |
19 |
13 |
Individual |
|
Defender |
1 |
5 |
2 |
Cumulative |
|
Developer Tools |
1 |
24 |
36 |
Cumulative |
|
Exchange Server |
1 |
5 |
4 |
Cumulative |
|
Microsoft Edge |
1 |
67 |
1 |
Cumulative |
|
Office |
1 |
90 |
11 |
Cumulative (except 2016) |
|
Office 2016 |
1 |
90 |
18 |
Individual |
|
Other |
1 |
6 |
4 |
Individual |
|
SharePoint Server |
1 |
18 |
3 |
Cumulative |
|
SQL Server |
1 |
8 |
8 |
Cumulative |
|
Windows |
1 |
421 |
35 |
Cumulative |
Notable CVEs
|
CVE ID |
Title |
Notable Item |
|
CVE-2026-50661 |
Windows BitLocker Security Feature Bypass Vulnerability |
Publicly Known |
|
CVE-2026-56155 |
Active Directory Federation Services Elevation of Privilege
Vulnerability |
Exploitation Detected |
|
CVE-2026-56164 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
Exploitation Detected |
|
CVE-2026-58644 |
Microsoft SharePoint Remote Code Execution Vulnerability |
Exploitation Detected |
We are republishing 867
non-Microsoft Chromium CVEs
Security Update
Guide Blog Posts
|
Date |
Blog Post |
|
October 31, 2025 |
You asked, we delivered: Introducing new features
for an improved security experience |
|
October 28, 2025 |
Understanding CVE-2025-55315: What CISOs,
security engineers, and sysadmins should know |
|
October 22, 2025 |
Toward greater transparency: Introducing
machine-readable Vulnerability Exploitability Xchange (VEX) for
Azure Linux and beyond |
|
November 12, 2024 |
Toward greater transparency: Publishing
machine-readable CSAF files |
|
June 27, 2024 |
Toward greater transparency: Unveiling Cloud
Service CVEs |
|
April 9, 2024 |
Toward greater transparency: Security Update
Guide now shares CWEs for CVEs |
|
January 6, 2023 |
Publishing CBL-Mariner CVEs on the Security
Update Guide CVRF API |
|
January 11, 2022 |
Coming Soon: New Security Update Guide
Notification System |
|
February 9, 2021 |
Continuing to Listen: Good News about the
Security Update Guide API |
|
January 13, 2021 |
Security Update Guide Supports CVEs Assigned by
Industry Partners |
|
December 8, 2020 |
Security Update Guide: Let’s keep the
conversation going |
|
November 9, 2020 |
Vulnerability Descriptions in the New Version of
the Security Update Guide |
Relevant
Resources
- The new Hotpatching feature is now generally
available. Please see Hotpatching
feature for Windows Server Azure Edition virtual machines (VMs) for
more information.
- Windows 10 and Windows 11 updates are cumulative. The monthly
security release includes all security fixes for vulnerabilities
that affect Windows 10 and Windows 11, in addition to non-security
updates. The updates are available via the Microsoft
Update Catalog. For information on lifecycle and support dates
for Windows 10 and Windows 11 operating systems, please see Windows
Lifecycle Facts Sheet.
- Microsoft is improving Windows Release Notes. For more
information, please see What's
next for Windows release notes.
- A list of the latest servicing stack updates for each operating
system can be found in ADV990001.
This list will be updated whenever a new servicing stack update is
released. It is important to install the latest servicing stack
update.
- In addition to security changes for the vulnerabilities, updates
include defense-in-depth updates to help improve security-related
features.
- Customers running Windows Server 2008 R2, or Windows Server 2008
need to purchase the Extended Security Update to continue receiving
security updates. See 4522133 for
more information.
Known Issues
You can see these in more detail from the Deployments
tab by selecting Known Issues column in the Edit
Columns panel.
For more information about Windows Known Issues, please see Windows
message center (links to currently-supported versions of Windows are
in the left pane).