Skip to content

Vendors

Microsoft

356records157productslast change2026-09-04RSSas of the 2026-09-07 snapshot

Rows per week, last 26 weeks

338 rows in the last 26 weeks, 11 in the week to 2026-09-0711 this week

When Microsoft edits: same day → over a year

microsoft: 218 counted rows by the interval to the first recorded revision: 6 same day, 9 1 to 7 days, 102 8 to 30 days, 72 31 to 90 days, 23 91 to 365 days, 6 over a year218 counted rows as publisher

Rows, not records: one record that changed for four products is four rows and one record. 132 of the 356 records raised a stated fix version; that is the count the publisher scorecard rates.

Every change, newest first

lines 21 to 40 of 212 · standing on 118 of 690 rows
Every counted change to a CVE or CISA KEV record naming Microsoft, newest first. A line standing for the same change across several records or products says how many and opens to every one.
Changed on, The day the commit that carried this change was read. Where the same change spans several days, the first and the last, never a midpoint. Not dated means no commit could be located for the row.ChangeCVEProductWhat the record says now
2026-08-14Fix version movedCVE-2026-32202Windows 11 Version 26h1stated at publication 10.0.28000.1836, now states 10.0.28000.2525
2026-08-14Fix version movedCVE-2026-322022 productsstated at publication 6.2.9200.26026, now states 6.2.9200.26226
2026-08-14Fix version movedCVE-2026-32202Windows Server 2012stated at publication 6.2.9200.26026, now states 6.2.9200.26226
2026-08-14Fix version movedCVE-2026-32202Windows Server 2012 (Server Core Installation)stated at publication 6.2.9200.26026, now states 6.2.9200.26226
2026-08-14Fix version movedCVE-2026-322022 productsstated at publication 6.3.9600.23132, now states 6.3.9600.23291
2026-08-14Fix version movedCVE-2026-32202Windows Server 2012 r2stated at publication 6.3.9600.23132, now states 6.3.9600.23291
2026-08-14Fix version movedCVE-2026-32202Windows Server 2012 r2 (Server Core Installation)stated at publication 6.3.9600.23132, now states 6.3.9600.23291
2026-08-14Fix version movedCVE-2026-32202Windows Server 2022stated at publication 10.0.20348.5020, now states 10.0.20348.5386
2026-08-14Fix version movedCVE-2026-322022 productsstated at publication 10.0.26100.32690, now states 10.0.26100.33158
2026-08-14Fix version movedCVE-2026-32202Windows Server 2025stated at publication 10.0.26100.32690, now states 10.0.26100.33158
2026-08-14Fix version movedCVE-2026-32202Windows Server 2025 (Server Core Installation)stated at publication 10.0.26100.32690, now states 10.0.26100.33158
2026-08-13Product addedOffice Online Servernot named as affected at publication, now names office online server
2026-08-13Product addedCVE-2026-68817Office Online Servernot named as affected at publication, now names office online server
2026-08-13Product addedCVE-2026-68814Office Online Servernot named as affected at publication, now names office online server
23 more rows in this change are not listed here. Open all 25 rows
2026-08-11Added to CISA KEVCVE-2026-68820Windows Ancillary Function Driver for WinSocklisted by CISA 2026-08-11federal fix due 2026-08-25
2026-08-11Product addedCVE-2026-59118Copilot Coworknot named as affected at publication, now names copilot cowork
2026-08-10Ransomware use confirmedCVE-2026-45659SharePoint Serverstated at publication Unknown, now states Known
2026-07-28Fix version movedMicrosoft Exchange Server 2016 Cumulative Update 23stated at publication 15.01.2507.069, now states 15.01.2507.071
2026-07-28Fix version movedCVE-2026-47631Microsoft Exchange Server 2016 Cumulative Update 23stated at publication 15.01.2507.069, now states 15.01.2507.071
2026-07-28Fix version movedCVE-2026-45504Microsoft Exchange Server 2016 Cumulative Update 23stated at publication 15.01.2507.069, now states 15.01.2507.071
5 more rows in this change are not listed here. Open all 7 rows
2026-07-28Fix version movedMicrosoft Exchange Server 2019 Cumulative Update 14stated at publication 15.02.1544.041, now states 15.02.1544.043
2026-07-28Fix version movedCVE-2026-47631Microsoft Exchange Server 2019 Cumulative Update 14stated at publication 15.02.1544.041, now states 15.02.1544.043
2026-07-28Fix version movedCVE-2026-45504Microsoft Exchange Server 2019 Cumulative Update 14stated at publication 15.02.1544.041, now states 15.02.1544.043
5 more rows in this change are not listed here. Open all 7 rows
2026-07-28Fix version movedMicrosoft Exchange Server 2019 Cumulative Update 15stated at publication 15.02.1748.046, now states 15.02.1748.048
2026-07-28Fix version movedCVE-2026-47631Microsoft Exchange Server 2019 Cumulative Update 15stated at publication 15.02.1748.046, now states 15.02.1748.048
2026-07-28Fix version movedCVE-2026-45504Microsoft Exchange Server 2019 Cumulative Update 15stated at publication 15.02.1748.046, now states 15.02.1748.048
5 more rows in this change are not listed here. Open all 7 rows
2026-07-28Fix version movedMicrosoft Exchange Server Subscription Edition Rtmstated at publication 15.02.2562.043, now states 15.02.2562.045
2026-07-28Fix version movedCVE-2026-47631Microsoft Exchange Server Subscription Edition Rtmstated at publication 15.02.2562.043, now states 15.02.2562.045
2026-07-28Fix version movedCVE-2026-45504Microsoft Exchange Server Subscription Edition Rtmstated at publication 15.02.2562.043, now states 15.02.2562.045
5 more rows in this change are not listed here. Open all 7 rows
2026-07-26Product addedCVE-2026-485612 productsnot named as affected at publication, now names 2 products
2026-07-26Product addedCVE-2026-48561Microsoft Edge Copilot For Androidnot named as affected at publication, now names microsoft edge copilot for android
2026-07-26Product addedCVE-2026-48561Microsoft Edge Copilot For iOSnot named as affected at publication, now names microsoft edge copilot for ios
2026-07-22Added to CISA KEVCVE-2026-50522SharePointlisted by CISA 2026-07-22federal fix due 2026-07-25
2026-07-22Fix version moved.net 10.0stated at publication 10.0.6, now states 10.0.10
2026-07-22Fix version movedCVE-2026-50659.net 10.0stated at publication 10.0.6, now states 10.0.10
2026-07-22Fix version movedCVE-2026-50651.net 10.0stated at publication 10.0.6, now states 10.0.10
9 more rows in this change are not listed here. Open all 11 rows
2026-05-11 to2026-07-22Product addedMicrosoft .net Framework 4.8.1not named as affected at publication, now names microsoft .net framework 4.8.1
2026-07-22Product addedCVE-2026-50659Microsoft .net Framework 4.8.1not named as affected at publication, now names microsoft .net framework 4.8.1
2026-07-22Product addedCVE-2026-50649Microsoft .net Framework 4.8.1not named as affected at publication, now names microsoft .net framework 4.8.1
11 more rows in this change are not listed here. Open all 13 rows
2026-07-21 to2026-07-22Product addedCVE-2026-473045 productsnot named as affected at publication, now names 5 products
2026-07-22Product addedCVE-2026-47304.net 10.0not named as affected at publication, now names .net 10.0
2026-07-22Product addedCVE-2026-47304.net 8.0not named as affected at publication, now names .net 8.0
3 more rows in this change are not listed here. Open all 5 rows
2024-01-09 to2026-07-21Product addedMicrosoft Visual Studio 2019 Version 16.11 (Includes 16.0 - 16.10)not named as affected at publication, now names microsoft visual studio 2019 version 16.11 (includes 16.0 - 16.10)
2026-07-21Product addedCVE-2026-47304Microsoft Visual Studio 2019 Version 16.11 (Includes 16.0 - 16.10)not named as affected at publication, now names microsoft visual studio 2019 version 16.11 (includes 16.0 - 16.10)
2024-09-10Product addedCVE-2024-35272Microsoft Visual Studio 2019 Version 16.11 (Includes 16.0 - 16.10)not named as affected at publication, now names microsoft visual studio 2019 version 16.11 (includes 16.0 - 16.10)
7 more rows in this change are not listed here. Open all 9 rows
2026-05-14 to2026-07-16Product addedMicrosoft .net Framework 3.5 And 4.7.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2
2026-07-16Product addedCVE-2026-50647Microsoft .net Framework 3.5 And 4.7.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2
2026-07-16Product addedCVE-2026-50411Microsoft .net Framework 3.5 And 4.7.2not named as affected at publication, now names microsoft .net framework 3.5 and 4.7.2
11 more rows in this change are not listed here. Open all 13 rows

A line that names a count is the same change on that many records or products, shown once; it opens to every member. A closed line is not reached by find-in-page; the flat view (Every row, flat →) is. Only counted changes are here: a change a kind's false-positive filter refused, such as a product line being renumbered, is in no figure on this page.

Data sources and quality

One vendor, every counted kind of change: the rows where a CVE record or a CISA KEV entry naming Microsoft changed after publication. The vendor name is the record's own text, compared without regard to case, so one organisation can appear under more than one spelling and this page holds the spellings that share its web address. Rows and records are different numbers and are never added together.

Not counted: a product line being renumbered, a boundary already named in the record's own description, and the other refusal classes are filtered as false positives and are in no figure here, so this page is what survived those filters rather than everything the catalog changed for this vendor.

Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, and a CISA KEV listing added before the first mirrored commit was never seen changing, so an absence from this page is not evidence that a record held.

How every one of these figures is measured, in full →

Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.