Skip to content

Vendors

Microsoft

356records157productslast change2026-09-04RSSas of the 2026-09-07 snapshot

Rows per week, last 26 weeks

338 rows in the last 26 weeks, 11 in the week to 2026-09-0711 this week

When Microsoft edits: same day → over a year

microsoft: 218 counted rows by the interval to the first recorded revision: 6 same day, 9 1 to 7 days, 102 8 to 30 days, 72 31 to 90 days, 23 91 to 365 days, 6 over a year218 counted rows as publisher

Rows, not records: one record that changed for four products is four rows and one record. 132 of the 356 records raised a stated fix version; that is the count the publisher scorecard rates.

Every change, newest first

lines 61 to 80 of 212 · standing on 29 of 690 rows
Every counted change to a CVE or CISA KEV record naming Microsoft, newest first. A line standing for the same change across several records or products says how many and opens to every one.
Changed on, The day the commit that carried this change was read. Where the same change spans several days, the first and the last, never a midpoint. Not dated means no commit could be located for the row.ChangeCVEProductWhat the record says now
2026-05-20Added to CISA KEVCVE-2010-0249Internet Explorerlisted by CISA 2026-06-03federal fix due 2026-06-03
2026-05-20Added to CISA KEVCVE-2010-0806Internet Explorerlisted by CISA 2026-05-20federal fix due 2026-06-03
2026-05-20Added to CISA KEVDefenderlisted by CISA 2026-05-20federal fix due 2026-06-03
2026-05-20Added to CISA KEVCVE-2026-41091Defenderlisted by CISA 2026-05-20federal fix due 2026-06-03
2026-05-20Added to CISA KEVCVE-2026-45498Defenderlisted by CISA 2026-05-20federal fix due 2026-06-03
2026-05-15Product addedCVE-2026-40379Microsoft Entranot named as affected at publication, now names microsoft entra
2026-05-15Added to CISA KEVCVE-2026-42897Microsoftlisted by CISA 2026-05-15federal fix due 2026-05-29
2026-05-13Fix version movedMicrosoft Dynamics 365 (on-premises) Version 9.1stated at publication 9.1.44.15, now states 9.1.45.11
2026-05-13Fix version movedCVE-2026-42833Microsoft Dynamics 365 (on-premises) Version 9.1stated at publication 9.1.44.15, now states 9.1.45.11
2026-05-13Fix version movedCVE-2026-42898Microsoft Dynamics 365 (on-premises) Version 9.1stated at publication 9.1.44.15, now states 9.1.45.11
2026-05-11Fix version movedCVE-2026-20841Windows Notepadstated at publication 11.2510, now states 11.2512.26.0
2026-04-10 to2026-05-11Fix version movedVisual Studio Codestated at publication 1.109.2, now states 1.110.1
2026-05-11Fix version movedCVE-2026-21523Visual Studio Codestated at publication 1.109.2, now states 1.110.1
2026-04-10Fix version movedCVE-2026-21518Visual Studio Codestated at publication 1.109.2, now states 1.110.1
2026-05-11Product addedCVE-2026-32226Microsoft .net Framework 4.7.2not named as affected at publication, now names microsoft .net framework 4.7.2
2026-04-28Product addedCVE-2026-40372Microsoft Visual Studio 2026 Version 18.5not named as affected at publication, now names microsoft visual studio 2026 version 18.5
2026-04-28Added to CISA KEVCVE-2026-32202Windowslisted by CISA 2026-04-28federal fix due 2026-05-12
2025-01-29 to2026-04-22Product addedPowershell 7.5not named as affected at publication, now names powershell 7.5
2026-04-22Product addedCVE-2026-26171Powershell 7.5not named as affected at publication, now names powershell 7.5
2025-09-11Product addedCVE-2025-49734Powershell 7.5not named as affected at publication, now names powershell 7.5
5 more rows in this change are not listed here. Open all 7 rows
2026-04-22Product addedCVE-2026-26171Powershell 7.6not named as affected at publication, now names powershell 7.6
2026-04-22Added to CISA KEVCVE-2026-33825Defenderlisted by CISA 2026-04-22federal fix due 2026-05-06
2026-04-21Ransomware use confirmedCVE-2023-21529Exchange Serverstated at publication Unknown, now states Known
2026-04-21Product addedCVE-2026-32203Microsoft Visual Studio 2026 Version 18.4not named as affected at publication, now names microsoft visual studio 2026 version 18.4
2026-04-14Added to CISA KEVCVE-2009-0238Officelisted by CISA 2026-04-14federal fix due 2026-04-28
2026-04-14Added to CISA KEVCVE-2026-32201SharePoint Serverlisted by CISA 2026-04-14federal fix due 2026-04-28
2026-04-13Added to CISA KEVCVE-2012-1854Visual Basic for Applications (VBA)listed by CISA 2026-04-13federal fix due 2026-04-27
2026-04-13Added to CISA KEVCVE-2023-21529Exchange Serverlisted by CISA 2026-04-13federal fix due 2026-04-27

A line that names a count is the same change on that many records or products, shown once; it opens to every member. A closed line is not reached by find-in-page; the flat view (Every row, flat →) is. Only counted changes are here: a change a kind's false-positive filter refused, such as a product line being renumbered, is in no figure on this page.

Data sources and quality

One vendor, every counted kind of change: the rows where a CVE record or a CISA KEV entry naming Microsoft changed after publication. The vendor name is the record's own text, compared without regard to case, so one organisation can appear under more than one spelling and this page holds the spellings that share its web address. Rows and records are different numbers and are never added together.

Not counted: a product line being renumbered, a boundary already named in the record's own description, and the other refusal classes are filtered as false positives and are in no figure here, so this page is what survived those filters rather than everything the catalog changed for this vendor.

Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, and a CISA KEV listing added before the first mirrored commit was never seen changing, so an absence from this page is not evidence that a record held.

How every one of these figures is measured, in full →

Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.