Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

HighMicrosoft MSRC

CVE-2026-88097

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-0899

Out of bounds memory access in V8 in Microsoft Edge vulnerability

Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-87701

Azure Cosmos DB Elevation of Privilege vulnerability

Azure Cosmos DB Elevation of Privilege vulnerability (CVE-2026-87701) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-85917

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85917) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-85889

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85889) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85885

Microsoft 365 Copilot Elevation of Privilege vulnerability

Microsoft 365 Copilot Elevation of Privilege vulnerability (CVE-2026-85885) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-85878

Azure Database for PostgreSQL Elevation of Privilege vulnerability

Azure Database for PostgreSQL Elevation of Privilege vulnerability (CVE-2026-85878) was added to Microsoft’s security update guidance. <p>Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-83946

Azure Portal Spoofing vulnerability

Azure Portal Spoofing vulnerability (CVE-2026-83946) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-83944

Azure Logic Apps Elevation of Privilege vulnerability

Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-83944) was added to Microsoft’s security update guidance. <p>Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-78501

Microsoft 365 Copilot Business Chat Information Disclosure vulnerability

Microsoft 365 Copilot Business Chat Information Disclosure vulnerability (CVE-2026-78501) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77903

Microsoft Dataverse Elevation of Privilege vulnerability

Microsoft Dataverse Elevation of Privilege vulnerability (CVE-2026-77903) was added to Microsoft’s security update guidance. <p>Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-70200

Azure Logic Apps Elevation of Privilege vulnerability

Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-70200) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70009

Azure Arc Elevation of Privilege vulnerability

Azure Arc Elevation of Privilege vulnerability (CVE-2026-70009) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69865

Microsoft Container Registry Elevation of Privilege vulnerability

Microsoft Container Registry Elevation of Privilege vulnerability (CVE-2026-69865) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-69843

Microsoft Fabric Elevation of Privilege vulnerability

Microsoft Fabric Elevation of Privilege vulnerability (CVE-2026-69843) was added to Microsoft’s security update guidance. <p>Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69399

Azure Arc Elevation of Privilege vulnerability

Azure Arc Elevation of Privilege vulnerability (CVE-2026-69399) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68794

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-68794) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68791

Azure Machine Learning Information Disclosure vulnerability

Azure Machine Learning Information Disclosure vulnerability (CVE-2026-68791) was added to Microsoft’s security update guidance. <p>Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-62874

Azure Billing Elevation of Privilege vulnerability

Azure Billing Elevation of Privilege vulnerability (CVE-2026-62874) was added to Microsoft’s security update guidance. <p>Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62819

Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability

Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-62819) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56176

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-56176) was added to Microsoft’s security update guidance. Added Office software to the Security Updates table. Customers that are running supported version of Office are encouraged to update to the indicated version to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55946

Microsoft Copilot Information Disclosure vulnerability

Microsoft Copilot Information Disclosure vulnerability (CVE-2026-55946) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55121

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55121) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55039

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55039) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.