Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-78462

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-78462) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78461

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-78461) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78457

Windows Security Health Service Elevation of Privilege vulnerability

Windows Security Health Service Elevation of Privilege vulnerability (CVE-2026-78457) was added to Microsoft’s security update guidance. <p>Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78456

SQL Server Remote Code Execution vulnerability

SQL Server Remote Code Execution vulnerability (CVE-2026-78456) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78454

Windows CD-ROM Driver Information Disclosure vulnerability

Windows CD-ROM Driver Information Disclosure vulnerability (CVE-2026-78454) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-78453

Microsoft Windows SCSI Class System File Information Disclosure vulnerability

Microsoft Windows SCSI Class System File Information Disclosure vulnerability (CVE-2026-78453) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78452

Microsoft Windows SCSI Class System File Information Disclosure vulnerability

Microsoft Windows SCSI Class System File Information Disclosure vulnerability (CVE-2026-78452) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78451

Microsoft Windows SCSI Class System File Elevation of Privilege vulnerability

Microsoft Windows SCSI Class System File Elevation of Privilege vulnerability (CVE-2026-78451) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78450

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability (CVE-2026-78450) was added to Microsoft’s security update guidance. <p>Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78449

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability (CVE-2026-78449) was added to Microsoft’s security update guidance. <p>Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78448

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-78448) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78447

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-78447) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78446

Windows Distributed File System (DFS) Denial of Service vulnerability

Windows Distributed File System (DFS) Denial of Service vulnerability (CVE-2026-78446) was added to Microsoft’s security update guidance. <p>Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78445

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability (CVE-2026-78445) was added to Microsoft’s security update guidance. <p>Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78444

Microsoft Failover Cluster Remote Code Execution vulnerability

Microsoft Failover Cluster Remote Code Execution vulnerability (CVE-2026-78444) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78442

Windows OLE DB Remote Code Execution vulnerability

Windows OLE DB Remote Code Execution vulnerability (CVE-2026-78442) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78441

Windows OLE DB Information Disclosure vulnerability

Windows OLE DB Information Disclosure vulnerability (CVE-2026-78441) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-78439

Microsoft Office Graphics Component Remote Code Execution vulnerability

Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-78439) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77911

Microsoft Office Word Information Disclosure vulnerability

Microsoft Office Word Information Disclosure vulnerability (CVE-2026-77911) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77909

Azure CycleCloud Information Disclosure vulnerability

Azure CycleCloud Information Disclosure vulnerability (CVE-2026-77909) was added to Microsoft’s security update guidance. <p>Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77908

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-77908) was added to Microsoft’s security update guidance. <p>Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77907

Visual Studio Remote Code Execution vulnerability

Visual Studio Remote Code Execution vulnerability (CVE-2026-77907) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77906

Visual Studio Remote Code Execution vulnerability

Visual Studio Remote Code Execution vulnerability (CVE-2026-77906) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77905

Windows Management Instrumentation Elevation of Privilege vulnerability

Windows Management Instrumentation Elevation of Privilege vulnerability (CVE-2026-77905) was added to Microsoft’s security update guidance. <p>Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.