Microsoft security briefs
3328 published alerts for Microsoft products and services.
Heap buffer overflow GPU in Microsoft Edge vulnerability
Heap buffer overflow GPU in Microsoft Edge vulnerability (CVE-2026-12010) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input Accessibility in Microsoft Edge vulnerability
Insufficient validation of untrusted input Accessibility in Microsoft Edge vulnerability (CVE-2026-12009) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free DigitalCredentials in Microsoft Edge vulnerability
Use after free DigitalCredentials in Microsoft Edge vulnerability (CVE-2026-12008) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free Core in Microsoft Edge vulnerability
Use after free Core in Microsoft Edge vulnerability (CVE-2026-12007) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/search/label/Desktop%20Update) for more information. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-48569) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47298) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-47294) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability
Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass vulnerability (CVE-2026-45482) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number and Title as the Chat extention is now merged into Visual Studio Code If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Elevation of Privilege vulnerability
Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-40376) was added to Microsoft’s security update guidance. Updated the Security Updates Build Number If you need help checking exposure, call (864) 335-9223.
Microsoft PC Manager Elevation of Privilege vulnerability
Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-50512) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft PC Manager Elevation of Privilege vulnerability
Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-50511) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows NTLM Spoofing vulnerability
Windows NTLM Spoofing vulnerability (CVE-2026-50508) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Windows BitLocker Security Feature Bypass vulnerability
Windows BitLocker Security Feature Bypass vulnerability (CVE-2026-50507) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. If you need help checking exposure, call (864) 335-9223.
Microsoft PC Manager Security Feature Bypass vulnerability
Microsoft PC Manager Security Feature Bypass vulnerability (CVE-2026-49161) was added to Microsoft’s security update guidance. Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-48583) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Media Remote Code Execution vulnerability
Windows Media Remote Code Execution vulnerability (CVE-2026-48574) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Narrator Braille Elevation of Privilege vulnerability
Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-48565) was added to Microsoft’s security update guidance. Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-48562) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-48560) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Windows Boot Manager Security Feature Bypass vulnerability
Windows Boot Manager Security Feature Bypass vulnerability (CVE-2026-47656) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Remote Code Execution vulnerability
Windows Hyper-V Remote Code Execution vulnerability (CVE-2026-47652) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Storage Elevation of Privilege vulnerability
Windows Storage Elevation of Privilege vulnerability (CVE-2026-47648) was added to Microsoft’s security update guidance. Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Azure Stack Edge Remote Code Execution vulnerability
Azure Stack Edge Remote Code Execution vulnerability (CVE-2026-47643) was added to Microsoft’s security update guidance. External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47641) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.