Microsoft's Security Update Guide published a batch of new vulnerability records spanning multiple CVE-2026-* identifiers, including CVE-2026-40369, CVE-2026-8548, CVE-2026-8535, CVE-2026-6472, CVE-2026-44431, CVE-2026-41090, CVE-2026-23663, CVE-2026-8522, CVE-2026-29518, CVE-2026-44608, CVE-2026-47784, CVE-2026-26110, CVE-2026-23672, CVE-2026-24300, and CVE-2026-21509. The entries appeared across both vulnerability and advisory pages on MSRC, indicating a coordinated publication of newly tracked Microsoft security issues.
The available references provide little technical detail beyond the identifiers and their presence in the MSRC portal, and several pages returned placeholder or "Not found" titles at the time of collection. Even so, the volume of newly listed CVEs signals ongoing expansion of Microsoft's disclosed vulnerability inventory, and defenders should monitor the corresponding MSRC records for severity ratings, affected products, exploitability assessments, and patch guidance as those details are populated.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
The references show Microsoft Security Response Center pages for multiple 2026 CVEs and advisories becoming available in the Security Update Guide. No technical details, impact information, or remediation specifics are provided in the source content.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
39 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.