Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-13793

Insufficient policy enforcement in SVG in Microsoft Edge vulnerability

Insufficient policy enforcement in SVG in Microsoft Edge vulnerability (CVE-2026-13793) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13790

Side-channel information leakage in Scroll in Microsoft Edge vulnerability

Side-channel information leakage in Scroll in Microsoft Edge vulnerability (CVE-2026-13790) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13787

Use after free in Chromoting in Microsoft Edge vulnerability

Use after free in Chromoting in Microsoft Edge vulnerability (CVE-2026-13787) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13786

Use after free in Ozone in Microsoft Edge vulnerability

Use after free in Ozone in Microsoft Edge vulnerability (CVE-2026-13786) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13784

Use after free in Views in Microsoft Edge vulnerability

Use after free in Views in Microsoft Edge vulnerability (CVE-2026-13784) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13783

Use after free in Views in Microsoft Edge vulnerability

Use after free in Views in Microsoft Edge vulnerability (CVE-2026-13783) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13782

Use after free in Browser in Microsoft Edge vulnerability

Use after free in Browser in Microsoft Edge vulnerability (CVE-2026-13782) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13781

Insufficient validation of untrusted input in Skia in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Skia in Microsoft Edge vulnerability (CVE-2026-13781) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13780

Insufficient validation of untrusted input in ANGLE in Microsoft Edge vulnerability

Insufficient validation of untrusted input in ANGLE in Microsoft Edge vulnerability (CVE-2026-13780) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13779

Use after free in Chromoting in Microsoft Edge vulnerability

Use after free in Chromoting in Microsoft Edge vulnerability (CVE-2026-13779) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13776

Type Confusion in Dawn in Microsoft Edge vulnerability

Type Confusion in Dawn in Microsoft Edge vulnerability (CVE-2026-13776) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13775

Use after free in GPU in Microsoft Edge vulnerability

Use after free in GPU in Microsoft Edge vulnerability (CVE-2026-13775) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13774

Use after free in Extensions in Microsoft Edge vulnerability

Use after free in Extensions in Microsoft Edge vulnerability (CVE-2026-13774) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57100

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability (CVE-2026-57100) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54998

Microsoft Exchange Online Elevation of Privilege vulnerability

Microsoft Exchange Online Elevation of Privilege vulnerability (CVE-2026-54998) was added to Microsoft’s security update guidance. Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50521

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-50521) was added to Microsoft’s security update guidance. Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41106

Microsoft 365 Copilot Elevation of Privilege vulnerability

Microsoft 365 Copilot Elevation of Privilege vulnerability (CVE-2026-41106) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-26145

Microsoft Azure Synapse Elevation of Privilege vulnerability

Microsoft Azure Synapse Elevation of Privilege vulnerability (CVE-2026-26145) was added to Microsoft’s security update guidance. Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-45659

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45659). Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. CISA remediation due date: 2026-07-04. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32208

Microsoft Entra ID Spoofing vulnerability

Microsoft Entra ID Spoofing vulnerability (CVE-2026-32208) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-42910

Windows Hotpatch Monitoring Service Elevation of Privilege vulnerability

Windows Hotpatch Monitoring Service Elevation of Privilege vulnerability (CVE-2026-42910) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13038

Use after free in Autofill in Microsoft Edge vulnerability

Use after free in Autofill in Microsoft Edge vulnerability (CVE-2026-13038) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13036

Use after free in Blink in Microsoft Edge vulnerability

Use after free in Blink in Microsoft Edge vulnerability (CVE-2026-13036) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13035

Use after free in Bluetooth in Microsoft Edge vulnerability

Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-13035) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.