Microsoft

Security Scorecard

Score

25F

Total CVEs

634

Patch Rate

27%

172 patched

Avg Response

1052d

days to patch

Critical Gaps

35

exploitable, no detection

Severity Breakdown

Critical15
High294
Medium264
Low40

Patch Status

Patched172 (27%)
Partial/Workaround31 (5%)
Unpatched431 (68%)

CVEs (644)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-24888Maker.js Vector Line Drawing ExploitMedium6.5-Patched
CVE-2025-41727Device Manager BypassHigh7.8-Patched
CVE-2025-41728Device Manager Web Service RCEMedium5.3-Patched
CVE-2026-21509Windows Server Local Privilege EscalationHigh7.8-Workaround
CVE-2026-24304Azure Resource Manager Privilege EscalationCritical9.9-Patched
CVE-2026-0758mcp-server-siri-shortcuts Shortcut InjectionHigh7.8-Patched
CVE-2026-23988Rufus Bootloader ExploitHigh7.3-Patched
CVE-2026-21227Azure Logic Apps Path Traversal VulnerabilityHigh8.2-Patched
CVE-2026-21264CVE-2026-21264Critical9.3-Patched
CVE-2026-21520Copilot Studio Data ExposureHigh7.5-Workaround