← Home
August 2026 Early Security Updates
Source: microsoft / 2026-Aug
— original advisory
Published: 2026-08-06
· Last updated: 2026-08-06
· Vendor severity: Critical
CVEs
| CVE | CVSS | CWE | Exploitation |
| CVE-2026-49163 |
8.8 |
CWE-22: Path Traversal |
Not observed in the wild |
| CVE-2026-50481 |
9.9 |
CWE-471 |
Not observed in the wild |
| CVE-2026-50515 |
9.9 |
CWE-502: Deserialization of Untrusted Data |
Not observed in the wild |
| CVE-2026-50516 |
Not yet scored |
CWE-306: Missing Authentication for Critical Function |
Not observed in the wild |
| CVE-2026-56161 |
9.6 |
CWE-284: Improper Access Control |
Not observed in the wild |
| CVE-2026-56162 |
10.0 |
CWE-287: Improper Authentication |
Not observed in the wild |
| CVE-2026-59115 |
9.9 |
CWE-35 |
Not observed in the wild |
| CVE-2026-59118 |
9.3 |
CWE-285: Improper Authorization |
Not observed in the wild |
| CVE-2026-62830 |
9.9 |
CWE-862: Missing Authorization |
Not observed in the wild |
| CVE-2026-62836 |
8.7 |
CWE-923 |
Not observed in the wild |
| CVE-2026-62869 |
Not yet scored |
CWE-345 |
Not observed in the wild |
| CVE-2026-62873 |
9.8 |
CWE-347 |
Not observed in the wild |
| CVE-2026-62896 |
9.6 |
CWE-287: Improper Authentication |
Not observed in the wild |
| CVE-2026-62918 |
7.5 |
CWE-347 |
Not observed in the wild |
| CVE-2026-63508 |
10.0 |
CWE-306: Missing Authentication for Critical Function |
Not observed in the wild |
| CVE-2026-63522 |
Not yet scored |
CWE-732 |
Not observed in the wild |
| CVE-2026-65667 |
10.0 |
CWE-862: Missing Authorization |
Not observed in the wild |
| CVE-2026-65668 |
8.8 |
CWE-284: Improper Access Control |
Not observed in the wild |
| CVE-2026-68823 |
9.1 |
CWE-749 |
Not observed in the wild |
| CVE-2026-70332 |
9.6 |
CWE-79: Cross-Site Scripting (XSS) |
Not observed in the wild |