← Back to Threat Radar·Vendor focus

Microsoft Vulnerabilities Affecting Small Businesses

Windows, Exchange Server, Microsoft 365, and Office vulnerabilities affecting small businesses.

575
Total CVEs
17
Critical
12
High risk
24
CISA KEV
Last updated: September 11, 2026 · Data: NVD · CISA KEV · EPSS
CVE-2025-53770criticalKEVEXPLOIT

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

95
SMB SCORE
CVSS 9.8
EPSS 90.5%
CVE-2026-21513criticalKEVEXPLOIT

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

90
SMB SCORE
CVSS 8.8
EPSS 4.8%
CVE-2025-54313criticalKEVEXPLOIT

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

89
SMB SCORE
CVSS 7.5
EPSS 6.7%
CVE-2026-3909criticalKEVEXPLOIT

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

89
SMB SCORE
CVSS 8.8
EPSS 27.1%
CVE-2026-21510criticalKEVEXPLOIT

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

88
SMB SCORE
CVSS 8.8
EPSS 3.1%
CVE-2026-3910criticalKEVEXPLOIT

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

87
SMB SCORE
CVSS 8.8
EPSS 21.9%
CVE-2025-2783criticalKEVEXPLOIT

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

87
SMB SCORE
CVSS 8.3
EPSS 35.4%
CVE-2025-24054criticalKEVEXPLOIT

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

84
SMB SCORE
CVSS 6.5
EPSS 11.9%
CVE-2026-21514criticalKEVEXPLOIT

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

80
SMB SCORE
CVSS 7.8
EPSS 5.1%
CVE-2026-21525criticalKEVEXPLOIT

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

78
SMB SCORE
CVSS 6.2
EPSS 3.4%
CVE-2026-21519criticalKEVEXPLOIT

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

78
SMB SCORE
CVSS 7.8
EPSS 3.1%
CVE-2026-5281criticalKEVEXPLOIT

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

78
SMB SCORE
CVSS 8.8
EPSS 3.0%
CVE-2026-21533criticalKEVEXPLOIT

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

77
SMB SCORE
CVSS 7.8
EPSS 2.7%
CVE-2025-13223criticalKEVEXPLOIT

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

76
SMB SCORE
CVSS 8.8
EPSS 2.1%
CVE-2026-2441criticalKEVEXPLOIT

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

75
SMB SCORE
CVSS 8.8
EPSS 0.1%
CVE-2025-26633criticalKEVEXPLOIT

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

71
SMB SCORE
CVSS 7.0
EPSS 6.4%
CVE-2025-24984criticalKEVEXPLOIT

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

70
SMB SCORE
CVSS 4.6
EPSS 5.0%
CVE-2025-24993highKEVEXPLOIT

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

64
SMB SCORE
CVSS 7.8
EPSS 1.5%
CVE-2025-24985highKEVEXPLOIT

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

63
SMB SCORE
CVSS 7.8
EPSS 1.1%
CVE-2025-13315high

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

61
SMB SCORE
CVSS 9.8
EPSS 82.4%
CVE-2025-24991highKEVEXPLOIT

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

61
SMB SCORE
CVSS 5.5
EPSS 0.7%
CVE-2025-24983highKEVEXPLOIT

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

60
SMB SCORE
CVSS 7.0
EPSS 0.7%
CVE-2026-81963highKEVEXPLOIT

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

60
SMB SCORE
CVSS 7.8
EPSS 0.6%
CVE-2025-62215highKEVEXPLOIT

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

60
SMB SCORE
CVSS 7.0
EPSS 0.6%
CVE-2026-85880highKEVEXPLOIT

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

60
SMB SCORE
CVSS 7.8
EPSS 0.6%
CVE-2025-24071high

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

59
SMB SCORE
CVSS 6.5
EPSS 57.6%
CVE-2025-13316high

Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server.

57
SMB SCORE
CVSS 8.1
EPSS 72.0%
CVE-2025-53771high

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

57
SMB SCORE
CVSS 6.5
EPSS 39.6%
CVE-2025-29814high

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

54
SMB SCORE
CVSS 9.3
EPSS 18.9%
CVE-2025-29806medium

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

42
SMB SCORE
CVSS 6.5
EPSS 1.6%
CVE-2025-62204medium

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

41
SMB SCORE
CVSS 8.0
EPSS 1.7%
CVE-2026-64901medium

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

40
SMB SCORE
CVSS 8.8
EPSS 1.6%
CVE-2026-69342medium

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

40
SMB SCORE
CVSS 7.5
EPSS 1.1%
CVE-2026-81385medium

Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.

40
SMB SCORE
CVSS 8.8
EPSS 1.1%
CVE-2026-63516medium

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

39
SMB SCORE
CVSS 6.5
EPSS 1.2%
CVE-2026-63514medium

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

39
SMB SCORE
CVSS 8.8
EPSS 1.3%
CVE-2026-72977medium

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 1.0%
CVE-2026-78509medium

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

39
SMB SCORE
CVSS 9.8
EPSS 1.0%
CVE-2026-78515medium

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-80073medium

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-72938medium

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-72974medium

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-78510medium

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

39
SMB SCORE
CVSS 9.8
EPSS 0.9%
CVE-2026-80079medium

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-80088medium

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-78503medium

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-69497medium

Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.

39
SMB SCORE
CVSS 6.5
EPSS 1.1%
CVE-2026-69739medium

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-69626medium

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

39
SMB SCORE
CVSS 6.5
EPSS 0.9%
CVE-2026-78518medium

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

39
SMB SCORE
CVSS 8.8
EPSS 0.9%
Related — other vendors affecting SMB
Fortinet vulnerabilities →Cisco vulnerabilities →SonicWall vulnerabilities →Apache vulnerabilities →WordPress vulnerabilities →Veeam vulnerabilities →Synology vulnerabilities →QNAP vulnerabilities →