2026-10-04 11:08 CEST · Intelligence refreshed (Europe/Stockholm)
Understand software risk, with the evidence visible.
Search software, operating systems, packages, CVEs, KBs, campaigns, advisories, named operations or GHSAs and review correlated vulnerability, campaign, advisory, exploitation, update, affected-product and lifecycle intelligence in one place.
Latest synchronized CVE
CVSS 6.5Published 2026-09-30 14:45 CEST
Vendor
Affected products
1 affected products/devices1 software
General vulnerability queryRecent High & critical CVEs
Query the vulnerability time window. Default 7 days; narrow to the last 24 hours or expand to 14 or 30 days when needed.
34intelligence collections available
0related products displayed
12evidence categories matched
23unique affected products/devices
Correlated intelligenceChecked
NVD applicability intelligenceRelevant evidence found
ENISA EUVD intelligenceRelevant evidence found
Zero Day Initiative advisory intelligenceChecked
Zero Day Initiative upcoming disclosuresAvailable
Credential risk intelligenceAvailable
Public exploit evidenceChecked
Known exploitationChecked
Exploit probabilityRelevant evidence found
Security advisory intelligenceRelevant evidence found
2 related advisoriesNo reliable named campaign/operation extracted
16 downstreamAcross 1 vendor / product ecosystems
Affected operating systems
Microsoft Windows 10 Version 1607Microsoft Windows Server 2019 (Server Core installation)microsoft Windows Server 2022microsoft windows server 2025Microsoft Windows Server 2025 (Server Core installation)Microsoft Windows 10 Version 1809+32 more
Supply-chain / downstream exposureProducts linked downstream through explicit relationship evidence or vendor/product-status advisories. Generic campaign/IOC mentions are excluded from this supply-chain count.
Named campaigns are shown separately from generic advisory records. Both are direct contextual relationships because the source explicitly contains this CVE; neither implies every affected product shown elsewhere was used in the campaign.
Related advisories / campaign intelligence records
August 2026 Monthly Patch | Cyber Security Agency of Singapore Skip to main content A Singapore Government Agency Web…CSA / SingCERT · AL-2026-103
MS 8월 보안 위협에 따른 정기 보안 업데이트 권고KISA / KrCERT · KRCERT-7650FA6822EFA73B3D684DC3
Environment impact assessment
41unique affected products/devices
38operating systems
3software / applications
How can this affect my environment?
This is an exposure-oriented interpretation of the intelligence, not a claim that any asset in your environment is vulnerable. Confirm against your own inventory, versions, configurations and embedded components.
Operating-system relationships are represented in the affected-product evidence.
Software/application relationships are represented, including downstream products that may bundle the vulnerable component.
Check the affected-product inventory below against CMDB, software inventory, appliance/device inventory and dependency manifests.
For products that bundle the vulnerable component, validate the vendor's own advisory and fixed release rather than assuming the component version alone proves exposure.
Prioritize internet-facing, remotely reachable, unauthenticated, known-exploited and business-critical assets first when those signals are present.
This view separates downstream/bundled/advisory-derived exposure from direct product assertions. It is correlation evidence, not proof that every listed deployment is exploitable; vendor/version/configuration validation still applies.
16downstream products
1vendors / ecosystems
16OS/platform relationships
Representative downstream relationships
Microsoft Windows Server 2019 (Server Core installation)Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2022Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2025Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2025 (Server Core installation)Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012 (Server Core installation)Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012 R2Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2012 R2 (Server Core installation)Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2016Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2016 (Server Core installation)Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2019Operating systems and platforms · Product-associated assertion · NVD/CVE catalog · supporting vendor/advisory evidence
Microsoft Windows Server 2022 (Server Core installation)Operating systems and platforms · Product-associated assertion · Microsoft Kb · supporting vendor/advisory evidence
Complete downstream evidence
Every downstream product relationship Scantide currently correlates for this CVE is listed below. Expand a category to inspect all products and their provenance.
Operating systems and platforms · 16 relationships
Microsoft Windows 10 Version 1607 for 32-bit SystemsMicrosoft
Vendor/advisory-supportedProduct-associated AssertionSource: Microsoft Kbmedium-high confidence
Microsoft Windows 10 Version 1607 for x64-based SystemsMicrosoft
Vendor/advisory-supportedProduct-associated AssertionSource: Microsoft Kbmedium-high confidence
Microsoft Windows 10 Version 1809 for 32-bit SystemsMicrosoft
Vendor/advisory-supportedProduct-associated AssertionSource: Microsoft Kbmedium-high confidence
Microsoft Windows 10 Version 1809 for x64-based SystemsMicrosoft
Vendor/advisory-supportedProduct-associated AssertionSource: Microsoft Kbmedium-high confidence
Direct intelligence-source lanes: every lane below has direct evidence for
in that Scantide intelligence collection. Lanes share the CVE as their join key; their presence together does not imply that one source explicitly referenced another source's record.
These vendors are derived from affected product/device evidence tied to this CVE. This is intentionally separate from the direct intelligence-source lanes above: a vendor can have affected products without Scantide having a vendor-specific advisory or Microsoft KB record for the CVE.
1 affected vendors represented
Analyzer searches are accepted only from validated browser forms. CVE identifiers and campaign/advisory names also have strict read-only path-form permalinks for sharing.
View:
2026-10-04 11:08 CESTIntelligence refreshed
1unique CVEs queried and enriched
1unique CVEs correlated to this result
1unique advisories correlated
19intelligence collections queried
Affected software, operating systems, hardware and devices 41
Deduplicated across Scantide's structured CVE, NVD applicability, CSAF, vendor advisory, campaign and downstream product evidence. Taxonomy IDs and evidence-only identifiers are excluded from the asset count. Counts represent relationships Scantide can currently prove, not the theoretical maximum downstream ecosystem.
Operating systems and platformsAffected range: All listed or unspecified versionsProduct-associated Assertion
Primary: NVD applicability graph — official CPE Match expansionCorroborated: NVD/CVE catalog — official CPE Match expansionCorroborated: CISA Vulnrichment — official CPE Match expansionCorroborated: NVD applicability graphCorroborated: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kb — official CPE Match expansionCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platformsAffected range: All listed or unspecified versionsProduct-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platformsAffected range: All listed or unspecified versionsProduct-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platformsAffected range: All listed or unspecified versionsProduct-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platformsAffected range: All listed or unspecified versionsProduct-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platformsAffected range: All listed or unspecified versionsProduct-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platformsAffected range: All listed or unspecified versionsProduct-associated Assertion
Primary: NVD/CVE catalogCorroborated: CISA VulnrichmentCorroborated: Microsoft Kbhigh confidence
Vendor: Microsoft
Operating systems and platformsAffected range: version 10.0.14393.0 — before 10.0.14393.9418Product-associated Assertion
Microsoft CVE ↔ KB relationships from MSRC CVRF and Microsoft Support. Multiple rows can exist for one KB when product/build applicability or support-page evidence differs.
KB5120242
Windows Server 2022 (Server Core installation)Restart YesMSRC CVRF
Only sources that directly identify or describe the queried CVE are shown here. Historical examples from MITRE CWE definitions are kept in the weakness section and are not presented as related CVEs.
Correlated from multiple vulnerability, exploitation, advisory, package and affected-product intelligence collections.
Affected-product scope: The product/device count is the deduplicated set Scantide can prove from its currently ingested structured records and advisory text. It is not a claim that only those products were affected; component vulnerabilities such as Log4Shell can have a much larger downstream ecosystem. Advisory and vendor references are kept clickable so additional downstream exposure can be followed to the authoritative source.
Coverage note: Scantide correlates multiple public and locally indexed intelligence sources, but no dataset or matching process is complete. Results may omit software, dependencies, affected versions or advisories, and related records do not by themselves prove that a specific installation is vulnerable. Confirm important findings against vendor guidance and the installed product and version.