Microsoft
Security Scorecard
Score
25F
Total CVEs
634
Patch Rate
27%
172 patched
Avg Response
1052d
days to patch
Critical Gaps
35
exploitable, no detection
Severity Breakdown
Critical15
High294
Medium264
Low40
Patch Status
Patched172 (27%)
Partial/Workaround31 (5%)
Unpatched431 (68%)
CVEs (645)
| CVE ID | Title | Severity | Score | Days | Patch |
|---|---|---|---|---|---|
| CVE-2026-21521 | Copilot Vulnerability | High | 7.4 | - | Workaround |
| CVE-2026-21524 | Azure Data Explorer API Exposure | High | 7.4 | - | Patched |
| CVE-2026-24305 | Azure Entra ID Elevation of Privilege Vulnerability | Critical | 9.3 | - | Patched |
| CVE-2026-24306 | Azure Front Door (AFD) Privilege Escalation | Critical | 9.8 | - | Patched |
| CVE-2026-24307 | CVE-2026-24307 | Critical | 9.3 | - | Patched |
| CVE-2026-22463 | Micro.company Form to Chat App XSS | Medium | 6.5 | - | Patched |
| CVE-2021-47864 | OSAS Traverse Extension Unquoted Service Path Vulnerability | High | 7.8 | - | Patched |
| CVE-2025-53516 | MedDream PACS Premium XSS Vulnerability | Medium | 6.1 | - | Patched |
| CVE-2025-54157 | MedDream PACS Premium XSS Vulnerability | Medium | 6.1 | - | Patched |
| CVE-2021-47828 | Bootp Turbo Unquoted Service Path Vulnerability | High | 7.8 | - | Patched |