Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-12010

Heap buffer overflow GPU in Microsoft Edge vulnerability

Heap buffer overflow GPU in Microsoft Edge vulnerability (CVE-2026-12010) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-12009

Insufficient validation of untrusted input Accessibility in Microsoft Edge vulnerability

Insufficient validation of untrusted input Accessibility in Microsoft Edge vulnerability (CVE-2026-12009) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-12008

Use after free DigitalCredentials in Microsoft Edge vulnerability

Use after free DigitalCredentials in Microsoft Edge vulnerability (CVE-2026-12008) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-12007

Use after free Core in Microsoft Edge vulnerability

Use after free Core in Microsoft Edge vulnerability (CVE-2026-12007) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48569

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-48569) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47298

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47298) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47294

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47294) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45482

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability

Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability (CVE-2026-45482) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number and Title as the Chat extention is now merged into Visual Studio Code If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40376

Visual Studio Code Elevation of Privilege vulnerability

Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-40376) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50512

Microsoft PC Manager Elevation of Privilege vulnerability

Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-50512) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50511

Microsoft PC Manager Elevation of Privilege vulnerability

Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-50511) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50508

Windows NTLM Spoofing vulnerability

Windows NTLM Spoofing vulnerability (CVE-2026-50508) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50507

Windows BitLocker Security Feature Bypass vulnerability

Windows BitLocker Security Feature Bypass vulnerability (CVE-2026-50507) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49161

Microsoft PC Manager Security Feature Bypass vulnerability

Microsoft PC Manager Security Feature Bypass vulnerability (CVE-2026-49161) was added to Microsoft’s security update guidance. Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48583

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-48583) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48574

Windows Media Remote Code Execution vulnerability

Windows Media Remote Code Execution vulnerability (CVE-2026-48574) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48565

Windows Narrator Braille Elevation of Privilege vulnerability

Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-48565) was added to Microsoft’s security update guidance. Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48562

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-48562) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48560

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-48560) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47656

Windows Boot Manager Security Feature Bypass vulnerability

Windows Boot Manager Security Feature Bypass vulnerability (CVE-2026-47656) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47652

Windows Hyper-V Remote Code Execution vulnerability

Windows Hyper-V Remote Code Execution vulnerability (CVE-2026-47652) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47648

Windows Storage Elevation of Privilege vulnerability

Windows Storage Elevation of Privilege vulnerability (CVE-2026-47648) was added to Microsoft’s security update guidance. Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47643

Azure Stack Edge Remote Code Execution vulnerability

Azure Stack Edge Remote Code Execution vulnerability (CVE-2026-47643) was added to Microsoft’s security update guidance. External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47641

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47641) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.