Microsoft security briefs
3328 published alerts for Microsoft products and services.
Use after free in WebShare in Microsoft Edge vulnerability
Use after free in WebShare in Microsoft Edge vulnerability (CVE-2026-12437) was added to Microsoft’s security update guidance. Corrected CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Azure Synapse Elevation of Privilege vulnerability
Microsoft Azure Synapse Elevation of Privilege vulnerability (CVE-2026-48584) was added to Microsoft’s security update guidance. Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Online Elevation of Privilege vulnerability
Microsoft Exchange Online Elevation of Privilege vulnerability (CVE-2026-48582) was added to Microsoft’s security update guidance. Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Dynamics 365 Elevation of Privilege vulnerability
Dynamics 365 Elevation of Privilege vulnerability (CVE-2026-47647) was added to Microsoft’s security update guidance. Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Dynamics 365 Customer Voice Spoofing vulnerability
Dynamics 365 Customer Voice Spoofing vulnerability (CVE-2026-47646) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft 365 Copilot's Business Chat Elevation of Privilege vulnerability
Microsoft 365 Copilot's Business Chat Elevation of Privilege vulnerability (CVE-2026-47645) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Cost Management Information Disclosure vulnerability
Microsoft Cost Management Information Disclosure vulnerability (CVE-2026-47633) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Azure Active Directory Elevation of Privilege vulnerability
Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-45480) was added to Microsoft’s security update guidance. Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Copilot Tampering vulnerability
Microsoft Copilot Tampering vulnerability (CVE-2026-42895) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.
Azure Bot Service Elevation of Privilege vulnerability
Azure Bot Service Elevation of Privilege vulnerability (CVE-2026-32174) was added to Microsoft’s security update guidance. Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47636) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Projected File System Elevation of Privilege vulnerability
Windows Projected File System Elevation of Privilege vulnerability (CVE-2026-42828) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Dynamic Host Configuration Protocol (DHCP) Tampering vulnerability
Windows Dynamic Host Configuration Protocol (DHCP) Tampering vulnerability (CVE-2026-45602) was added to Microsoft’s security update guidance. Updated CWE value. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 (on-premises) Elevation of Privilege vulnerability
Microsoft Dynamics 365 (on-premises) Elevation of Privilege vulnerability (CVE-2026-40371) was added to Microsoft’s security update guidance. Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.… If you need help checking exposure, call (864) 335-9223.
Use after free in Tracing in Microsoft Edge vulnerability
Use after free in Tracing in Microsoft Edge vulnerability (CVE-2026-11701) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Bluetooth in Microsoft Edge vulnerability
Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-11700) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Bluetooth in Microsoft Edge vulnerability
Use after free in Bluetooth in Microsoft Edge vulnerability (CVE-2026-11699) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Microsoft Edge vulnerability (CVE-2026-11698) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Uninitialized Use in Video in Microsoft Edge vulnerability
Uninitialized Use in Video in Microsoft Edge vulnerability (CVE-2026-11697) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Inappropriate implementation in Passwords in Microsoft Edge vulnerability
Inappropriate implementation in Passwords in Microsoft Edge vulnerability (CVE-2026-11696) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in ServiceWorker in Microsoft Edge vulnerability
Use after free in ServiceWorker in Microsoft Edge vulnerability (CVE-2026-11695) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Inappropriate implementation in Plugins in Microsoft Edge vulnerability
Inappropriate implementation in Plugins in Microsoft Edge vulnerability (CVE-2026-11694) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Read Anything in Microsoft Edge vulnerability
Use after free in Read Anything in Microsoft Edge vulnerability (CVE-2026-11693) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in New Tab Page in Microsoft Edge vulnerability
Insufficient validation of untrusted input in New Tab Page in Microsoft Edge vulnerability (CVE-2026-11692) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.