Patch tracker / KB5002606
KB5002606
Microsoft security update released 2024-07-09. Fixes 4 CVEs.
HighCISA KEVRansomware
Download KB5002606
Get the official update for KB5002606. The download and file size for each supported product are on the Microsoft Update Catalog page.
Update summary
Released
2024-07-09
CVEs fixed
4
Max CVSS
7.5
Severity
High
Exploitation and severity
Fixes 4 CVEs. At least one is actively exploited (CISA KEV). Most severe CVSS 7.5 (High). EPSS exploit probability up to 55%. One is linked to ransomware.
Among the top 25% of tracked Microsoft updates by EPSS exploit probability.
What to do
Treat as urgent: it is being exploited in the wild (CISA KEV), so patch ahead of items that are not. Senserva flags whether KB5002606 is missing on your devices.
CVEs fixed by this update
Affected products
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.