CVE Program Terms of Use (SPDX identifier: cve-tou) ================================================================================================== This licence governs the CVE-derived columns of windows-10-missed-security-fixes-2026.csv and of the study's JSON endpoint. It is published here because the licence requires that MITRE's copyright designation AND this licence text are reproduced with any copy of that data. Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation. Licence text as published by SPDX (https://raw.githubusercontent.com/spdx/license-list-data/main/json/details/cve-tou.json), and as carried at https://www.cve.org/Legal/TermsOfUse: CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE(R)). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. DISCLAIMERS ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN PROVIDED BY MITRE ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. -------------------------------------------------------------------------------------------------- Other rights in the same download: - The CISA Known Exploited Vulnerabilities columns (in_cisa_kev, kev_date_added, kev_days_publication_to_listing, kev_known_ransomware_campaign_use, kev_vulnerability_name) are CC0 1.0 Universal. Use of that information does not authorise use of the CISA logo or the DHS seal, and is not an endorsement by CISA or DHS. - Servnet's own classification and derived tables (component_family, vuln_type, the monthly aggregates and the study's analysis) are CC BY 4.0, attributing 'Servnet Windows 10 Missed Security Fixes 2026' with a link to https://www.servnetuk.com/research/windows-10-missed-security-fixes-2026. - Figures attributed to Microsoft's Security Update Guide, and quotations from Microsoft's documentation and from the Euroconsumers letter, are cited under those sources' own terms. They are not licensed by Servnet and no row from them appears in the CSV.