← Back to Threat Radar·Vendor focus

Microsoft Vulnerabilities Affecting Small Businesses

Windows, Exchange Server, Microsoft 365, and Office vulnerabilities affecting small businesses.

383
Total CVEs
17
Critical
10
High risk
22
CISA KEV
Last updated: April 26, 2026 · Data: NVD · CISA KEV · EPSS
CVE-2025-53770criticalKEVEXPLOIT

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

95
SMB SCORE
CVSS 9.8
EPSS 90.5%
CVE-2026-21513criticalKEVEXPLOIT

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

90
SMB SCORE
CVSS 8.8
EPSS 4.8%
CVE-2025-54313criticalKEVEXPLOIT

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

89
SMB SCORE
CVSS 7.5
EPSS 6.7%
CVE-2026-3909criticalKEVEXPLOIT

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

89
SMB SCORE
CVSS 8.8
EPSS 27.1%
CVE-2026-21510criticalKEVEXPLOIT

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

88
SMB SCORE
CVSS 8.8
EPSS 3.1%
CVE-2026-3910criticalKEVEXPLOIT

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

87
SMB SCORE
CVSS 8.8
EPSS 21.9%
CVE-2025-2783criticalKEVEXPLOIT

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

87
SMB SCORE
CVSS 8.3
EPSS 35.4%
CVE-2025-24054criticalKEVEXPLOIT

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

84
SMB SCORE
CVSS 6.5
EPSS 11.9%
CVE-2026-21514criticalKEVEXPLOIT

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

80
SMB SCORE
CVSS 7.8
EPSS 5.1%
CVE-2026-21525criticalKEVEXPLOIT

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

78
SMB SCORE
CVSS 6.2
EPSS 3.4%
CVE-2026-21519criticalKEVEXPLOIT

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

78
SMB SCORE
CVSS 7.8
EPSS 3.1%
CVE-2026-5281criticalKEVEXPLOIT

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

78
SMB SCORE
CVSS 8.8
EPSS 3.0%
CVE-2026-21533criticalKEVEXPLOIT

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

77
SMB SCORE
CVSS 7.8
EPSS 2.7%
CVE-2025-13223criticalKEVEXPLOIT

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

76
SMB SCORE
CVSS 8.8
EPSS 2.1%
CVE-2026-2441criticalKEVEXPLOIT

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

75
SMB SCORE
CVSS 8.8
EPSS 0.1%
CVE-2025-26633criticalKEVEXPLOIT

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

71
SMB SCORE
CVSS 7.0
EPSS 6.4%
CVE-2025-24984criticalKEVEXPLOIT

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

70
SMB SCORE
CVSS 4.6
EPSS 5.0%
CVE-2025-24993highKEVEXPLOIT

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

64
SMB SCORE
CVSS 7.8
EPSS 1.5%
CVE-2025-24985highKEVEXPLOIT

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

63
SMB SCORE
CVSS 7.8
EPSS 1.1%
CVE-2025-13315high

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

61
SMB SCORE
CVSS 9.8
EPSS 82.4%
CVE-2025-24991highKEVEXPLOIT

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

61
SMB SCORE
CVSS 5.5
EPSS 0.7%
CVE-2025-24983highKEVEXPLOIT

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

60
SMB SCORE
CVSS 7.0
EPSS 0.7%
CVE-2025-62215highKEVEXPLOIT

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

60
SMB SCORE
CVSS 7.0
EPSS 0.6%
CVE-2025-24071high

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

59
SMB SCORE
CVSS 6.5
EPSS 57.6%
CVE-2025-13316high

Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server.

57
SMB SCORE
CVSS 8.1
EPSS 72.0%
CVE-2025-53771high

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

57
SMB SCORE
CVSS 6.5
EPSS 39.6%
CVE-2025-29814high

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

54
SMB SCORE
CVSS 9.3
EPSS 18.9%
CVE-2025-29806medium

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

42
SMB SCORE
CVSS 6.5
EPSS 1.6%
CVE-2025-62204medium

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

41
SMB SCORE
CVSS 8.0
EPSS 1.7%
CVE-2025-24996medium

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

38
SMB SCORE
CVSS 6.5
EPSS 0.8%
CVE-2025-29807medium

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

38
SMB SCORE
CVSS 8.7
EPSS 1.0%
CVE-2025-59245medium

Microsoft SharePoint Online Elevation of Privilege Vulnerability

37
SMB SCORE
CVSS 9.8
EPSS 0.6%
CVE-2025-24986medium

Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.

37
SMB SCORE
CVSS 6.5
EPSS 0.6%
CVE-2025-21247medium

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

36
SMB SCORE
CVSS 4.3
EPSS 0.5%
CVE-2025-24051medium

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

36
SMB SCORE
CVSS 8.8
EPSS 0.5%
CVE-2025-24056medium

Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.

36
SMB SCORE
CVSS 8.8
EPSS 0.5%
CVE-2025-26645medium

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

34
SMB SCORE
CVSS 8.8
EPSS 0.3%
CVE-2026-21531medium

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

34
SMB SCORE
CVSS 9.8
EPSS 0.3%
CVE-2025-24053medium

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

34
SMB SCORE
CVSS 7.2
EPSS 0.4%
CVE-2025-24064medium

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

33
SMB SCORE
CVSS 8.1
EPSS 0.5%
CVE-2025-24035medium

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

33
SMB SCORE
CVSS 8.1
EPSS 0.5%
CVE-2025-62222medium

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.

33
SMB SCORE
CVSS 8.8
EPSS 0.2%
CVE-2024-8196medium

In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.

33
SMB SCORE
CVSS 9.8
EPSS 0.2%
CVE-2025-24045medium

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

32
SMB SCORE
CVSS 8.1
EPSS 0.4%
CVE-2026-21511medium

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

32
SMB SCORE
CVSS 7.5
EPSS 0.2%
CVE-2025-60724medium

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

32
SMB SCORE
CVSS 9.8
EPSS 0.1%
CVE-2025-12428medium

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

32
SMB SCORE
CVSS 8.8
EPSS 0.1%
CVE-2024-51477medium

IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.

32
SMB SCORE
CVSS 4.3
EPSS 0.2%
CVE-2025-24076medium

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

32
SMB SCORE
CVSS 7.3
EPSS 1.6%
CVE-2025-24070medium

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

31
SMB SCORE
CVSS 7.0
EPSS 0.3%
Related — other vendors affecting SMB
Fortinet vulnerabilities →Cisco vulnerabilities →SonicWall vulnerabilities →Apache vulnerabilities →WordPress vulnerabilities →Veeam vulnerabilities →Synology vulnerabilities →QNAP vulnerabilities →