Skip to main content

CVE-2026-58638

Windows Boot Loader Security Feature Bypass vulnerability

Microsoft

MSRC advisory July 14, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-58638
Affected products
Windows Boot Loader Security Feature Bypass · Microsoft Windows Boot Loader Security Feature Bypass · Microsoft

What happened

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

What it means for your business

Windows Boot Loader Security Feature Bypass vulnerability (CVE-2026-58638) was added to Microsoft’s security update guidance. Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Sources

Related briefs

HighMicrosoft MSRC

CVE-2026-70125

Microsoft Outlook Remote Code Execution vulnerability

Microsoft Outlook Remote Code Execution vulnerability (CVE-2026-70125) was added to Microsoft’s security update guidance. Information published. This CVE was addressed by updates that were released in September 2026, but the CVE was inadvertently omitted from the September 2026 Security Updates. This is an informational change only. Customers who have already installed the September 2026 updates… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57091

Windows File History Service Elevation of Privilege vulnerability

Windows File History Service Elevation of Privilege vulnerability (CVE-2026-57091) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55134

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-55134) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63532

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-63532) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.