Skip to content

Microsoft Windows β€” Security Intelligence & Vulnerability Profile


ParameterTechnical Specification
Official NameMicrosoft Windows
Vendor / Projectmicrosoft
Canonical IDmicrosoft:windows
Versioning Schemegeneric
CPE Identifierscpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Overall PostureCRITICAL
Recommended Safe ReleaseKB5051234 (Windows July 2025 Security Update)

Documented CVEs

25 vulnerabilities cataloged in the Hermes intelligence repository.

CISA KEV Entries

9 flaws with confirmed active in-the-wild exploitation.

Weaponized Exploits

24 vulnerabilities with publicly available PoCs or weaponized exploit tooling.

Remediation Target

Recommended upgrade to KB5051234 (Windows July 2025 Security Update) to neutralize known flaws.


Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:

Current HTS Score

0 / 100

= Stable over 30d

Max EPSS (Exploitation)

77.2 %

= Stable over 30d

CISA KEV Activity

9

Active in-the-wild exploitation

HTS Trend Curve (D-30 β†’ Today)2026-08-12 β†’ 2026-09-10
2026-09-08: KEV: CVE-2026-819632026-09-10: CVE: CVE-2026-33825

3. Vulnerability History & Version Applicability Matrix

Section titled β€œ3. Vulnerability History & Version Applicability Matrix”
CVECVSS ScoreEPSS ProbabilityCISA KEVAffected VersionsFixed InHermes Analysis
CVE-2026-695799.8 (CRITICAL)1.0%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-695959.8 (CRITICAL)1.0%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-697309.8 (CRITICAL)1.0%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-698459.8 (CRITICAL)0.9%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-729799.8 (CRITICAL)1.0%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-729829.8 (CRITICAL)0.9%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-730099.8 (CRITICAL)0.9%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-774939.8 (CRITICAL)1.0%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-784459.8 (CRITICAL)0.9%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-785099.8 (CRITICAL)1.0%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-695188.8 (CRITICAL)0.8%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-696038.8 (CRITICAL)0.3%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-696768.8 (CRITICAL)1.1%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-800838.8 (CRITICAL)0.2%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2021-422788.8 (HIGH)73.3%CISA KEVAll versions, All versions, All versions, All versionsKB5008102, KB5008380Analysis β†’
CVE-2021-422878.8 (HIGH)77.2%CISA KEVAll versions, All versions, All versions, All versionsKB5008102, KB5008380Analysis β†’
CVE-2026-729618.2 (HIGH)0.3%No< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-215107.8 (HIGH)26.2%CISA KEV< v10.0.26100.188210.0.26100.1882Analysis β†’
CVE-2026-338257.8 (HIGH)6.7%CISA KEV< v1.1.24080.91.1.24080.9Analysis β†’
CVE-2026-819637.8 (HIGH)0.6%CISA KEV< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2026-858807.8 (HIGH)0.6%CISA KEV< v10.0.19045.5780, < v10.0.22631.5280, < v10.0.26100.380010.0.19045.5780, 10.0.22631.5280, 10.0.26100.3800Analysis β†’
CVE-2025-298247.8 (HIGH)13.9%CISA KEV< v10.0.19045.5728, < v10.0.22631.5206, < v10.0.26100.375010.0.19045.5728, 10.0.22631.5206, 10.0.26100.3750Analysis β†’
CVE-2025-213337.8 (HIGH)10.0%CISA KEV< v10.0.19045.5371, < v10.0.22631.4751, < v10.0.26100.289410.0.19045.5371, 10.0.22631.4751, 10.0.26100.2894Analysis β†’
CVE-2025-327247.5 (HIGH)1.8%No< v10.0.10240.21034KB5051234 (Windows July 2025 Security Update)Analysis β†’
CVE-2025-240546.5 (MEDIUM)58.9%CISA KEV< v10.0.19045.5609, < v10.0.22631.5039, < v10.0.26100.347610.0.19045.5609, 10.0.22631.5039, 10.0.26100.3476Analysis β†’

Vulnerabilities impacting Microsoft Windows are actively leveraged in real-world intrusion campaigns:


Are you operating Microsoft Windows in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: