Microsoft

Security Scorecard

Score

25F

Total CVEs

641

Patch Rate

28%

178 patched

Avg Response

1052d

days to patch

Critical Gaps

35

exploitable, no detection

Severity Breakdown

Critical17
High299
Medium264
Low40

Patch Status

Patched178 (28%)
Partial/Workaround31 (5%)
Unpatched432 (67%)

CVEs (645)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-20957Excel Integer Overflow VulnerabilityHigh7.8-Patched
CVE-2026-20958MS Office SharePoint SSRFMedium5.4-Workaround
CVE-2026-20959Cross-Site Scripting in Microsoft Office SharePointMedium4.6-Patched
CVE-2026-20962DRTM Resource Disclosure VulnerabilityMedium4.4-Workaround
CVE-2026-20965Windows Admin Center Privilege EscalationHigh7.5-Patched
CVE-2026-21219Inbox COM Object Use After Free VulnerabilityHigh7.0-Patched
CVE-2026-21224Azure Connected Machine Agent VulnerabilityHigh7.8-Patched
CVE-2020-36911Covenant RCECritical9.8-Patched
CVE-2026-21226Azure Core Shared Client Library Deserialization VulnerabilityHigh7.5-Patched
CVE-2025-66620MicroServer Webshell ExploitHigh8.0-Patched