Microsoft security briefs
3323 published alerts for Microsoft products and services.
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Out of bounds memory access in V8 in Microsoft Edge vulnerability
Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Azure Cosmos DB Elevation of Privilege vulnerability
Azure Cosmos DB Elevation of Privilege vulnerability (CVE-2026-87701) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure AI Foundry Elevation of Privilege vulnerability
Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85917) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure AI Foundry Elevation of Privilege vulnerability
Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-85889) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft 365 Copilot Elevation of Privilege vulnerability
Microsoft 365 Copilot Elevation of Privilege vulnerability (CVE-2026-85885) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Database for PostgreSQL Elevation of Privilege vulnerability
Azure Database for PostgreSQL Elevation of Privilege vulnerability (CVE-2026-85878) was added to Microsoft’s security update guidance. <p>Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Portal Spoofing vulnerability
Azure Portal Spoofing vulnerability (CVE-2026-83946) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Logic Apps Elevation of Privilege vulnerability
Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-83944) was added to Microsoft’s security update guidance. <p>Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft 365 Copilot Business Chat Information Disclosure vulnerability
Microsoft 365 Copilot Business Chat Information Disclosure vulnerability (CVE-2026-78501) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Dataverse Elevation of Privilege vulnerability
Microsoft Dataverse Elevation of Privilege vulnerability (CVE-2026-77903) was added to Microsoft’s security update guidance. <p>Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Logic Apps Elevation of Privilege vulnerability
Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-70200) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Arc Elevation of Privilege vulnerability
Azure Arc Elevation of Privilege vulnerability (CVE-2026-70009) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Container Registry Elevation of Privilege vulnerability
Microsoft Container Registry Elevation of Privilege vulnerability (CVE-2026-69865) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Fabric Elevation of Privilege vulnerability
Microsoft Fabric Elevation of Privilege vulnerability (CVE-2026-69843) was added to Microsoft’s security update guidance. <p>Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Arc Elevation of Privilege vulnerability
Azure Arc Elevation of Privilege vulnerability (CVE-2026-69399) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-68794) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Azure Machine Learning Information Disclosure vulnerability
Azure Machine Learning Information Disclosure vulnerability (CVE-2026-68791) was added to Microsoft’s security update guidance. <p>Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Billing Elevation of Privilege vulnerability
Azure Billing Elevation of Privilege vulnerability (CVE-2026-62874) was added to Microsoft’s security update guidance. <p>Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-62819) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-56176) was added to Microsoft’s security update guidance. Added Office software to the Security Updates table. Customers that are running supported version of Office are encouraged to update to the indicated version to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.
Microsoft Copilot Information Disclosure vulnerability
Microsoft Copilot Information Disclosure vulnerability (CVE-2026-55946) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-55121) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55039) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.