CVE-2026-45649
Office for Android Spoofing vulnerability
Microsoft·Office for Android Spoofing
MSRC advisory June 9, 2026
Alert details
- Source feed
- Microsoft MSRC
- CVE ID
- CVE-2026-45649
- Affected products
- Office for Android Spoofing · Microsoft Office for Android Spoofing · Microsoft
What happened
Microsoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability.
What it means for your business
Office for Android Spoofing vulnerability (CVE-2026-45649) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Word, PowerPoint, Excel for Android. Customers running affected Microsoft Office for Android software should install the update for their product to be protected from this vulnerability. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Sources
Related briefs
Windows PowerShell Remote Code Execution vulnerability
Windows PowerShell Remote Code Execution vulnerability (CVE-2026-40400) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Active Directory Elevation of Privilege vulnerability
Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-50481) was added to Microsoft’s security update guidance. Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Service Bus Remote Code Execution vulnerability
Azure Service Bus Remote Code Execution vulnerability (CVE-2026-50515) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability
Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-50516) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.