Skip to content

Vendors

Microsoft

356records157productslast change2026-09-04RSSas of the 2026-09-07 snapshot

Rows per week, last 26 weeks

338 rows in the last 26 weeks, 11 in the week to 2026-09-0711 this week

When Microsoft edits: same day → over a year

microsoft: 218 counted rows by the interval to the first recorded revision: 6 same day, 9 1 to 7 days, 102 8 to 30 days, 72 31 to 90 days, 23 91 to 365 days, 6 over a year218 counted rows as publisher

Rows, not records: one record that changed for four products is four rows and one record. 132 of the 356 records raised a stated fix version; that is the count the publisher scorecard rates.

Every change, newest first

lines 181 to 200 of 212 · standing on 65 of 690 rows
Every counted change to a CVE or CISA KEV record naming Microsoft, newest first. A line standing for the same change across several records or products says how many and opens to every one.
Changed on, The day the commit that carried this change was read. Where the same change spans several days, the first and the last, never a midpoint. Not dated means no commit could be located for the row.ChangeCVEProductWhat the record says now
2024-05-15Fix version movedCVE-2024-30041Microsoft Bing Search For iOSstated at publication 28.2.000000000, now states 28.2.420417001
2024-05-14Fix version movedWindows 10 Version 1809stated at publication 10.0.17763.5696, now states 10.0.17763.5820
2024-05-14Fix version movedCVE-2024-28900Windows 10 Version 1809stated at publication 10.0.17763.5696, now states 10.0.17763.5820
2024-05-14Fix version movedCVE-2024-26217Windows 10 Version 1809stated at publication 10.0.17763.5696, now states 10.0.17763.5820
3 more rows in this change are not listed here. Open all 5 rows
2024-05-08Fix version movedCVE-2024-290592 productsstated at publication 3.0.50727.8975, now states 3.0.50727.8976
2024-05-08Fix version movedCVE-2024-29059Microsoft .net Framework 2.0 Service Pack 2stated at publication 3.0.50727.8975, now states 3.0.50727.8976
2024-05-08Fix version movedCVE-2024-29059Microsoft .net Framework 3.0 Service Pack 2stated at publication 3.0.50727.8975, now states 3.0.50727.8976
2024-05-08Fix version movedCVE-2024-29059Microsoft .net Framework 3.5 And 4.8.1stated at publication 4.8.9206.0, now states 4.8.09214.01
2024-04-23Fix version movedCVE-2024-26198Microsoft Exchange Server 2016 Cumulative Update 23stated at publication 15.01.2507.037, now states 15.01.2507.039
2024-04-23Fix version movedCVE-2024-26198Microsoft Exchange Server 2019 Cumulative Update 13stated at publication 15.02.1258.032, now states 15.02.1544.011
2023-06-30 to2024-04-16Product addedPowershell 7.3not named as affected at publication, now names powershell 7.3
2024-04-16Product addedCVE-2024-21409Powershell 7.3not named as affected at publication, now names powershell 7.3
2024-04-16Product addedCVE-2024-26190Powershell 7.3not named as affected at publication, now names powershell 7.3
12 more rows in this change are not listed here. Open all 14 rows
2024-04-11Product addedCVE-2024-21330Azure Hdinsightnot named as affected at publication, now names azure hdinsight
2024-03-22Product addedCVE-2024-00574 productsnot named as affected at publication, now names 4 products
2024-03-22Product addedCVE-2024-0057NuGet 17.4.0not named as affected at publication, now names nuget 17.4.0
2024-03-22Product addedCVE-2024-0057NuGet 17.6.0not named as affected at publication, now names nuget 17.6.0
2 more rows in this change are not listed here. Open all 4 rows
2024-03-22Fix version movedCVE-2024-21388Microsoft Edge (chromium-based)stated at publication 121.0.2277.83, now states 121.0.2277.98
2024-03-22Product addedCVE-2024-206773d Viewernot named as affected at publication, now names 3d viewer
2024-03-19Product addedCVE-2024-2169Wdsnot named as affected at publication, now names wds
2024-01-26 to2024-03-15Product addedMicrosoft Edge (chromium-based) Extended Stablenot named as affected at publication, now names microsoft edge (chromium-based) extended stable
2024-03-15Product addedCVE-2024-26163Microsoft Edge (chromium-based) Extended Stablenot named as affected at publication, now names microsoft edge (chromium-based) extended stable
2024-01-26Product addedCVE-2024-21337Microsoft Edge (chromium-based) Extended Stablenot named as affected at publication, now names microsoft edge (chromium-based) extended stable
2024-03-12Product addedMicrosoft Visio 2016not named as affected at publication, now names microsoft visio 2016
2024-03-12Product addedCVE-2023-35372Microsoft Visio 2016not named as affected at publication, now names microsoft visio 2016
2024-03-12Product addedCVE-2023-36866Microsoft Visio 2016not named as affected at publication, now names microsoft visio 2016
2024-01-12Product addedCVE-2024-21307Remote Desktop Client For Windows Desktopnot named as affected at publication, now names remote desktop client for windows desktop
2024-01-09Product addedMicrosoft Visual Studio 2022 Version 17.2not named as affected at publication, now names microsoft visual studio 2022 version 17.2
2024-01-09Product addedCVE-2023-29349Microsoft Visual Studio 2022 Version 17.2not named as affected at publication, now names microsoft visual studio 2022 version 17.2
2024-01-09Product addedCVE-2023-32028Microsoft Visual Studio 2022 Version 17.2not named as affected at publication, now names microsoft visual studio 2022 version 17.2
4 more rows in this change are not listed here. Open all 6 rows
2024-01-09Product addedMicrosoft Visual Studio 2022 Version 17.4not named as affected at publication, now names microsoft visual studio 2022 version 17.4
2024-01-09Product addedCVE-2023-29349Microsoft Visual Studio 2022 Version 17.4not named as affected at publication, now names microsoft visual studio 2022 version 17.4
2024-01-09Product addedCVE-2023-32028Microsoft Visual Studio 2022 Version 17.4not named as affected at publication, now names microsoft visual studio 2022 version 17.4
4 more rows in this change are not listed here. Open all 6 rows
2023-11-30Fix version movedCVE-2023-36796Microsoft Visual Studio 2022 Version 17.7stated at publication 17.7.4, now states 17.7.6
2023-11-06Product addedMicrosoft .net Framework 3.5 And 4.6.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.6.2
2023-11-06Product addedCVE-2023-36788Microsoft .net Framework 3.5 And 4.6.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.6.2
2023-11-06Product addedCVE-2023-36792Microsoft .net Framework 3.5 And 4.6.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.6.2
5 more rows in this change are not listed here. Open all 7 rows
2023-11-06Product addedMicrosoft .net Framework 3.5 And 4.6.2/4.7/4.7.1/4.7.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.6.2/4.7/4.7.1/4.7.2
2023-11-06Product addedCVE-2023-36788Microsoft .net Framework 3.5 And 4.6.2/4.7/4.7.1/4.7.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.6.2/4.7/4.7.1/4.7.2
2023-11-06Product addedCVE-2023-36792Microsoft .net Framework 3.5 And 4.6.2/4.7/4.7.1/4.7.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.6.2/4.7/4.7.1/4.7.2
5 more rows in this change are not listed here. Open all 7 rows

A line that names a count is the same change on that many records or products, shown once; it opens to every member. A closed line is not reached by find-in-page; the flat view (Every row, flat →) is. Only counted changes are here: a change a kind's false-positive filter refused, such as a product line being renumbered, is in no figure on this page.

Data sources and quality

One vendor, every counted kind of change: the rows where a CVE record or a CISA KEV entry naming Microsoft changed after publication. The vendor name is the record's own text, compared without regard to case, so one organisation can appear under more than one spelling and this page holds the spellings that share its web address. Rows and records are different numbers and are never added together.

Not counted: a product line being renumbered, a boundary already named in the record's own description, and the other refusal classes are filtered as false positives and are in no figure here, so this page is what survived those filters rather than everything the catalog changed for this vendor.

Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, and a CISA KEV listing added before the first mirrored commit was never seen changing, so an absence from this page is not evidence that a record held.

How every one of these figures is measured, in full →

Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.