Microsoft
356records157productslast change2026-09-04RSSas of the 2026-09-07 snapshot
Rows per week, last 26 weeks
When Microsoft edits: same day → over a year
Rows, not records: one record that changed for four products is four rows and one record. 132 of the 356 records raised a stated fix version; that is the count the publisher scorecard rates.
Every change, newest first
lines 121 to 140 of 212 · standing on 39 of 690 rows| Changed on, The day the commit that carried this change was read. Where the same change spans several days, the first and the last, never a midpoint. Not dated means no commit could be located for the row. | Change | CVE | Product | What the record says now |
|---|---|---|---|---|
| 2025-09-09 | Fix version moved | CVE-2025-48807 | Windows Server 2022 | stated at publication 10.0.20348.3932, now states 10.0.20348.4171 |
| 2025-09-09 | Fix version moved | CVE-2025-48807 | Windows Server 2022, 23h2 Edition (Server Core Installation) | stated at publication 10.0.25398.1732, now states 10.0.25398.1849 |
| 2025-09-09 | Fix version moved | CVE-2025-21293 | 3 products | stated at publication 10.0.26100.2894, now states 10.0.26100.6584 |
| 2025-09-09 | Fix version moved | CVE-2025-21293 | Windows 11 Version 24h2 | stated at publication 10.0.26100.2894, now states 10.0.26100.6584 |
| 2025-09-09 | Fix version moved | CVE-2025-21293 | Windows Server 2025 | stated at publication 10.0.26100.2894, now states 10.0.26100.6584 |
| 1 more row in this change is not listed here. Open all 3 rows → | ||||
| 2025-08-15 | Product added | CVE-2025-50171 | 6 products | not named as affected at publication, now names 6 products |
| 2025-08-15 | Product added | CVE-2025-50171 | Windows 10 Version 21h2 | not named as affected at publication, now names windows 10 version 21h2 |
| 2025-08-15 | Product added | CVE-2025-50171 | Windows 10 Version 22h2 | not named as affected at publication, now names windows 10 version 22h2 |
| 4 more rows in this change are not listed here. Open all 6 rows → | ||||
| 2025-08-12 | Fix version moved | CVE-2025-53729 | Azure File Sync | stated at publication 18.0.0.0, now states 18.3.0.0 |
| 2025-08-12 | Added to CISA KEV | CVE-2007-0671 | Office | listed by CISA 2025-08-12federal fix due 2025-09-02 |
| 2025-08-12 | Added to CISA KEV | CVE-2013-3893 | Internet Explorer | listed by CISA 2025-08-12federal fix due 2025-09-02 |
| 2025-08-05 | KEV required action changed | SharePoint | CISA rewrote the required action | |
| 2025-08-05 | KEV required action changed | CVE-2025-49704 | SharePoint | CISA rewrote the required action |
| 2025-08-05 | KEV required action changed | CVE-2025-49706 | SharePoint | CISA rewrote the required action |
| 2025-04-07 to2025-08-05 | Ransomware use confirmed | SharePoint | stated at publication Unknown, now states Known | |
| 2025-08-05 | Ransomware use confirmed | CVE-2025-53770 | SharePoint | stated at publication Unknown, now states Known |
| 2025-07-25 | Ransomware use confirmed | CVE-2025-49704 | SharePoint | stated at publication Unknown, now states Known |
| 2 more rows in this change are not listed here. Open all 4 rows → | ||||
| 2025-08-05 | KEV required action changed | CVE-2025-53770 | SharePoint | CISA rewrote the required action |
| 2025-07-22 | Added to CISA KEV | SharePoint | listed by CISA 2025-07-22federal fix due 2025-07-23 | |
| 2025-07-22 | Added to CISA KEV | CVE-2025-49704 | SharePoint | listed by CISA 2025-07-22federal fix due 2025-07-23 |
| 2025-07-22 | Added to CISA KEV | CVE-2025-49706 | SharePoint | listed by CISA 2025-07-22federal fix due 2025-07-23 |
| 2025-07-21 | Added to CISA KEV | CVE-2025-53770 | SharePoint | listed by CISA 2025-07-20federal fix due 2025-07-21 |
| 2025-07-18 | Ransomware use confirmed | CVE-2019-0708 | Remote Desktop Services | stated at publication Unknown, now states Known |
| 2025-07-11 | Fix version moved | CVE-2025-47956 | Windows Security App | stated at publication 1000.27840.0.1000, now states 1000.27840.1000.0 |
| 2025-07-08 | Fix version moved | CVE-2024-49000 | Microsoft Sql Server 2016 Service Pack 3 (Gdr) | stated at publication 13.0.6455.2, now states 13.0.6460.7 |
| 2025-07-08 | Fix version moved | CVE-2024-49000 | Microsoft Sql Server 2016 Service Pack 3 Azure Connect Feature Pack | stated at publication 13.0.7050.2, now states 13.0.7055.9 |
| 2025-06-16 | Product added | CVE-2024-38179 | Azure Stack Os Hci | not named as affected at publication, now names azure stack os hci |
| 2025-05-22 | Fix version moved | CVE-2025-26646 | Microsoft Visual Studio 2022 Version 17.10 | stated at publication 17.10.14, now states 17.10.15 |
| 2025-05-15 | Product added | CVE-2025-32709 | 4 products | not named as affected at publication, now names 4 products |
| 2025-05-15 | Product added | CVE-2025-32709 | Windows Server 2008 r2 Service Pack 1 | not named as affected at publication, now names windows server 2008 r2 service pack 1 |
| 2025-05-15 | Product added | CVE-2025-32709 | Windows Server 2008 r2 Service Pack 1 (Server Core Installation) | not named as affected at publication, now names windows server 2008 r2 service pack 1 (server core installation) |
| 2 more rows in this change are not listed here. Open all 4 rows → | ||||
| 2025-05-13 | Added to CISA KEV | Windows | listed by CISA 2025-05-13federal fix due 2025-06-03 | |
| 2025-05-13 | Added to CISA KEV | CVE-2025-30397 | Windows | listed by CISA 2025-05-13federal fix due 2025-06-03 |
| 2025-05-13 | Added to CISA KEV | CVE-2025-30400 | Windows | listed by CISA 2025-05-13federal fix due 2025-06-03 |
| 3 more rows in this change are not listed here. Open all 5 rows → | ||||
A line that names a count is the same change on that many records or products, shown once; it opens to every member. A closed line is not reached by find-in-page; the flat view (Every row, flat →) is. Only counted changes are here: a change a kind's false-positive filter refused, such as a product line being renumbered, is in no figure on this page.
Data sources and quality
One vendor, every counted kind of change: the rows where a CVE record or a CISA KEV entry naming Microsoft changed after publication. The vendor name is the record's own text, compared without regard to case, so one organisation can appear under more than one spelling and this page holds the spellings that share its web address. Rows and records are different numbers and are never added together.
Not counted: a product line being renumbered, a boundary already named in the record's own description, and the other refusal classes are filtered as false positives and are in no figure here, so this page is what survived those filters rather than everything the catalog changed for this vendor.
Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, and a CISA KEV listing added before the first mirrored commit was never seen changing, so an absence from this page is not evidence that a record held.
How every one of these figures is measured, in full →
Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.