SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Vendor Security Posture Report Card: Microsoft Q2 2026

Vendor Security Posture Report Card: Microsoft Q2 2026

Microsoft’s Q2 2026 security posture is rated Needs Improvement. Three Patch Tuesday releases addressed 504 vulnerabilities, including 55 Critical issues and two vulnerabilities exploited in the wild.

Oct 9, 2026By Aditya Jha10 min read

Vendor Security Posture Report Card: Microsoft - Q2 2026

Reporting period: Q2 2026 (April 1 to June 30, 2026).

Vendor Summary

FieldAssessment
Vendor NameMicrosoft
Product Lines CoveredWindows client and server, Microsoft Office, SharePoint Server, Exchange Server, .NET, Visual Studio, Azure components, SQL Server, Hyper-V and other products represented in Microsoft's April, May and June 2026 security releases.
Reporting PeriodQ2 2026 (April 1–June 30, 2026)
Overall Posture RatingConcerning
Prior Period RatingNot available; this is Microsoft's first report card in the series.
Total CVEs Disclosed (Period)487 in the same-day Patch Tuesday cohorts: 167 in April, 120 in May and 200 in June.
Critical and High Severity CountUnavailable. A complete CVSS-based Critical-plus-High count cannot be reconstructed for the fixed 487-CVE cohort from Microsoft's subsequently revised live monthly records.
CVEs With Confirmed In-the-Wild Exploitation2 verified Q2 cases in the reviewed monthly releases: CVE-2026-32201 affecting SharePoint Server and CVE-2026-42897 affecting Exchange Server.

Rating Scale Reference

The rating scale applied consistently across every report card in this series, so that ratings remain comparable from one vendor and one period to the next:

RatingCriteria
StrongDisclosure volume and severity trend stable or improving, advisories timely and complete, no unpatched critical exposure at time of writing.
AdequatePosture broadly sound with isolated gaps, such as a delayed patch cycle or an incomplete advisory, that do not indicate a systemic pattern.
Needs ImprovementRecurring gaps across the period: repeated delayed patches, incomplete disclosures, or a rising severity trend.
ConcerningEvidence of a systemic issue: sustained critical exposure, exploitation preceding a patch, or a pattern of incomplete or delayed disclosure.

Introduction

This report evaluates Microsoft's Q2 2026 vulnerability disclosure and remediation performance from April 1 through June 30. The posture is rated Concerning because exploitation of CVE-2026-42897 preceded its permanent security update: Microsoft supplied emergency mitigation in May and released the Exchange security update on June 9.

Scope and Methodology

The quantitative scope uses same-day Patch Tuesday cohorts from Microsoft's scheduled April 14, May 12 and June 9 releases. A CVE is counted only when it appeared in the Microsoft release set published on that Patch Tuesday. The totals exclude Microsoft Edge or Chromium vulnerabilities fixed by Google, vulnerabilities Microsoft published earlier or later in the month, and cloud-service or third-party-component records outside those same-day sets. This convention produces 167, 120 and 200 CVEs respectively. An archived CVE-by-CVE list for these same-day cohorts is not included, so the historical membership and totals cannot be independently reproduced from the subsequently revised live release notes alone.

Evidence was reconciled against the April, May and June Microsoft Security Update Guide releases and their individual CVE records. Publicly disclosed and actively exploited classifications were treated separately.

Vulnerability Disclosure Volume and Trend

Microsoft's Q2 security workload remained high throughout the quarter and increased sharply in June:

  • April 14: 167 vulnerabilities, including 8 Critical issues and 2 zero-days.
  • May 12: 120 vulnerabilities, including 17 Microsoft-rated Critical issues and no zero-days.
  • June 9: 200 vulnerabilities, including 33 Microsoft-rated Critical issues and 6 zero-days: 5 publicly disclosed vulnerabilities and 1 actively exploited vulnerability.

Under this same-day convention, the three releases addressed 487 vulnerabilities. Contemporaneous Microsoft severity labels identify 8 Critical issues in April, 17 in May and 33 in June, for 58; those label counts are reported separately and are not presented as a CVSS-band total. May was the only month without a zero-day, while June had the quarter's largest same-day cohort.

Severity Distribution Analysis

The template calls for a Critical, High, Medium and Low distribution based on published CVSS base scores. A complete distribution for the fixed 487-CVE period cohort is unavailable: Microsoft's live April, May and June release documents have added or revised records since the releases, so their current CVSS rows do not reproduce the contemporaneous cohort used for the volume total. This is an explicit template deviation. The report does not substitute Microsoft's Critical and Important labels for CVSS bands.

CVSS bandPeriod-cohort count
Critical (9.0–10.0)Unavailable for the fixed cohort
High (7.0–8.9)Unavailable for the fixed cohort
Medium (4.0–6.9)Unavailable for the fixed cohort
Low (0.1–3.9)Unavailable for the fixed cohort

Under Microsoft's contemporaneous severity labels, Critical findings were 8 in April, 17 in May and 33 in June. June's 33 Microsoft-rated Critical vulnerabilities included 28 remote-code-execution issues. These Microsoft labels are operational context, not a CVSS distribution.

Patch and Remediation Timeliness

Microsoft maintained its predictable monthly release cadence and issued the majority of fixes with detailed product, severity, exploitation and deployment information. April's actively exploited SharePoint vulnerability, CVE-2026-32201, received a security update in the scheduled April release.

The main timing exception involved CVE-2026-42897. Microsoft published Exchange mitigation guidance on May 14 and distributed temporary protection through the Exchange Emergency Mitigation Service. It then released the permanent security update on June 9. Microsoft nevertheless continued recommending that customers retain the mitigation until the July 14 Exchange update; patch availability and the later mitigation-removal milestone are therefore reported separately.

A typical disclosure-to-patch interval cannot be determined from the reviewed monthly records because Microsoft ordinarily publishes vulnerability details with the corresponding update and does not provide a comparable pre-disclosure date for every CVE. The Exchange case is reported as a dated exception rather than used as a quarter-wide average.

Exploitation and Real-World Impact

Two Q2 vulnerabilities were confirmed exploited in the wild. CVE-2026-32201 affected SharePoint Server and was fixed in April. For CVE-2026-42897, Microsoft first published Exchange mitigation guidance on May 14 and then released the permanent security update on June 9. Microsoft continued recommending the mitigation until its July update. The Exchange flaw could enable attacker-controlled JavaScript to execute in a user's browser when a crafted message was opened through Outlook Web Access under the required conditions.

June's six zero-days comprise five vulnerabilities that were publicly disclosed before fixes and one vulnerability, CVE-2026-42897, that Microsoft identified as actively exploited. “Publicly disclosed” and “actively exploited” are separate classifications; the six should not be read as six exploited vulnerabilities.

Notable Incidents This Period

CVE-2026-42897: Exchange Server Spoofing

Microsoft addressed this actively exploited Exchange vulnerability with emergency mitigation guidance and service-delivered protection in May, followed by a permanent security update on June 9. Microsoft continued recommending that the mitigation remain in place until the July 14 update, after which it could be removed. Organizations therefore had to track mitigation status, June patch installation and the later mitigation-removal milestone separately.

CVE-2026-32201: SharePoint Server Spoofing

Microsoft described CVE-2026-32201 as an improper-input-validation vulnerability that could allow an unauthorized network attacker to perform spoofing and affect confidentiality and integrity. Its confirmed exploitation made the April security update an immediate priority for internet-facing SharePoint deployments.

Advisory and Communication Quality

Microsoft's Security Update Guide provides strong CVE-level detail, including affected products, severity, CVSS information, exploitation assessments, acknowledgements and update references. The standard Patch Tuesday schedule supports enterprise testing and change-management planning.

Usability is reduced by the size and fragmentation of the release data. Administrators must correlate operating-system builds, Office channels, server applications, cloud services and emergency mitigations across multiple records. The distinction between a mitigation and a complete update also requires careful communication so that temporary protection is not mistaken for final remediation.

Historical Trend Comparison

Comparison with a prior Microsoft report card is unavailable because this is the first Microsoft assessment in the series. Q2 2026 establishes the baseline for subsequent comparisons of disclosure volume, CVSS coverage, confirmed exploitation and remediation timing.

Risk Context for Organizations

Microsoft products commonly span identity, endpoint, productivity, collaboration, messaging, virtualization and cloud control planes. This breadth means a single monthly release can create competing priorities across domain controllers, Exchange and SharePoint servers, user endpoints, Office installations and Azure-connected workloads.

Organizations should prioritize actively exploited vulnerabilities first, followed by internet-facing systems, Critical remote-code-execution issues, identity infrastructure and vulnerabilities Microsoft marks as exploitation more likely. Unsupported or disconnected Exchange and SharePoint deployments require particular attention because automated mitigations and standard servicing assumptions may not apply.

Overall Posture Rating and Rationale

Overall Q2 rating: Concerning. Microsoft maintained a predictable patch cadence and published detailed guidance, and the Exchange timeline progressed from emergency mitigation in May to a permanent security update on June 9. Nevertheless, CVE-2026-42897 was exploited before that patch was available. As documented in Exploitation and Real-World Impact and Patch and Remediation Timeliness, that fact directly meets the rating scale's Concerning criterion; temporary mitigation reduced exposure but is not an exception in the defined scale.

Key Takeaways

  • Microsoft's Q2 2026 security posture is rated Concerning because exploitation of CVE-2026-42897 preceded its permanent security update.
  • The same-day April, May and June Patch Tuesday cohorts contained 487 vulnerabilities; Microsoft labeled 58 Critical, but a comparable CVSS Critical-plus-High total is unavailable.
  • CVE-2026-32201 in SharePoint Server and CVE-2026-42897 in Exchange Server were confirmed exploited in the wild.
  • June's six zero-days comprised five publicly disclosed vulnerabilities and one actively exploited vulnerability.
  • Exchange emergency mitigation was available in May, the permanent security update followed on June 9, and Microsoft recommended retaining the mitigation until its July update.

Conclusion

Microsoft's Q2 2026 security posture is rated Concerning. Monthly release discipline, detailed advisories and the June Exchange update are strengths, but exploitation before patch availability meets the defined threshold for the rating. Ongoing vendor and compliance monitoring should track exploited-vulnerability deployment, temporary mitigations and completed installation across the Microsoft estate.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Vendor Security Posture Report Card: Oracle - Q2 2026
Vendor Security Posture Report Card: Oracle - Q2 2026

CVE Research

Vendor Security Posture Report Card: Oracle - Q2 2026

Explore Oracle's Q2 2026 security posture, including disclosed vulnerabilities, critical CVEs, security updates, patch management trends, exploitation risks, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Vendor Security Posture Report Card: Cisco - Q2 2026
Vendor Security Posture Report Card: Cisco - Q2 2026

CVE Research

Vendor Security Posture Report Card: Cisco - Q2 2026

Explore Cisco's security posture in Q2 2026, covering disclosed vulnerabilities, critical security risks, patch management, exploitation trends, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Vendor Security Posture Report Card: Adobe - Q2 2026
Vendor Security Posture Report Card: Adobe - Q2 2026

CVE Research

Vendor Security Posture Report Card: Adobe - Q2 2026

Explore Adobe's security posture in Q2 2026, including disclosed vulnerabilities, critical security risks, patch management, exploitation trends, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
vulnerability researchCritical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

CVE Research

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026