Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-77495

Windows Imaging Component Remote Code Execution vulnerability

Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-77495) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77494

Windows DHCP Server Denial of Service vulnerability

Windows DHCP Server Denial of Service vulnerability (CVE-2026-77494) was added to Microsoft’s security update guidance. <p>Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77493

Windows Graphics Component Remote Code Execution vulnerability

Windows Graphics Component Remote Code Execution vulnerability (CVE-2026-77493) was added to Microsoft’s security update guidance. <p>Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77492

Windows Storage Port Driver Information Disclosure vulnerability

Windows Storage Port Driver Information Disclosure vulnerability (CVE-2026-77492) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77491

Windows GDI Information Disclosure vulnerability

Windows GDI Information Disclosure vulnerability (CVE-2026-77491) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77489

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-77489) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77488

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-77488) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77487

SQL Server Elevation of Privilege vulnerability

SQL Server Elevation of Privilege vulnerability (CVE-2026-77487) was added to Microsoft’s security update guidance. <p>Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77486

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-77486) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77485

SQL Server Elevation of Privilege vulnerability

SQL Server Elevation of Privilege vulnerability (CVE-2026-77485) was added to Microsoft’s security update guidance. <p>Use after free in SQL Server allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77484

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-77484) was added to Microsoft’s security update guidance. <p>Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77483

SQL Server Elevation of Privilege vulnerability

SQL Server Elevation of Privilege vulnerability (CVE-2026-77483) was added to Microsoft’s security update guidance. <p>Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77482

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-77482) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77481

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-77481) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77480

SQL Server Elevation of Privilege vulnerability

SQL Server Elevation of Privilege vulnerability (CVE-2026-77480) was added to Microsoft’s security update guidance. <p>Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73029

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-73029) was added to Microsoft’s security update guidance. <p>Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73028

SQL Server Elevation of Privilege vulnerability

SQL Server Elevation of Privilege vulnerability (CVE-2026-73028) was added to Microsoft’s security update guidance. <p>Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73026

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-73026) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73025

Windows iSCSI Security Feature Bypass vulnerability

Windows iSCSI Security Feature Bypass vulnerability (CVE-2026-73025) was added to Microsoft’s security update guidance. <p>Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73024

Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege vulnerability

Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege vulnerability (CVE-2026-73024) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73023

Windows Imaging Component Remote Code Execution vulnerability

Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-73023) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73022

Windows Modern Device Management (MDM) Elevation of Privilege vulnerability

Windows Modern Device Management (MDM) Elevation of Privilege vulnerability (CVE-2026-73022) was added to Microsoft’s security update guidance. <p>Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73021

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-73021) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-73020

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-73020) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.