Microsoft security briefs
3323 published alerts for Microsoft products and services.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-78462) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-78461) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Security Health Service Elevation of Privilege vulnerability
Windows Security Health Service Elevation of Privilege vulnerability (CVE-2026-78457) was added to Microsoft’s security update guidance. <p>Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
SQL Server Remote Code Execution vulnerability
SQL Server Remote Code Execution vulnerability (CVE-2026-78456) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows CD-ROM Driver Information Disclosure vulnerability
Windows CD-ROM Driver Information Disclosure vulnerability (CVE-2026-78454) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SCSI Class System File Information Disclosure vulnerability
Microsoft Windows SCSI Class System File Information Disclosure vulnerability (CVE-2026-78453) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SCSI Class System File Information Disclosure vulnerability
Microsoft Windows SCSI Class System File Information Disclosure vulnerability (CVE-2026-78452) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows SCSI Class System File Elevation of Privilege vulnerability
Microsoft Windows SCSI Class System File Elevation of Privilege vulnerability (CVE-2026-78451) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability (CVE-2026-78450) was added to Microsoft’s security update guidance. <p>Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability (CVE-2026-78449) was added to Microsoft’s security update guidance. <p>Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-78448) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-78447) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Distributed File System (DFS) Denial of Service vulnerability
Windows Distributed File System (DFS) Denial of Service vulnerability (CVE-2026-78446) was added to Microsoft’s security update guidance. <p>Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability (CVE-2026-78445) was added to Microsoft’s security update guidance. <p>Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Failover Cluster Remote Code Execution vulnerability
Microsoft Failover Cluster Remote Code Execution vulnerability (CVE-2026-78444) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows OLE DB Remote Code Execution vulnerability
Windows OLE DB Remote Code Execution vulnerability (CVE-2026-78442) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows OLE DB Information Disclosure vulnerability
Windows OLE DB Information Disclosure vulnerability (CVE-2026-78441) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Graphics Component Remote Code Execution vulnerability
Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-78439) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Information Disclosure vulnerability
Microsoft Office Word Information Disclosure vulnerability (CVE-2026-77911) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure CycleCloud Information Disclosure vulnerability
Azure CycleCloud Information Disclosure vulnerability (CVE-2026-77909) was added to Microsoft’s security update guidance. <p>Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-77908) was added to Microsoft’s security update guidance. <p>Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Visual Studio Remote Code Execution vulnerability
Visual Studio Remote Code Execution vulnerability (CVE-2026-77907) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Visual Studio Remote Code Execution vulnerability
Visual Studio Remote Code Execution vulnerability (CVE-2026-77906) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Management Instrumentation Elevation of Privilege vulnerability
Windows Management Instrumentation Elevation of Privilege vulnerability (CVE-2026-77905) was added to Microsoft’s security update guidance. <p>Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.