Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-47640

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47640) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47639

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47639) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47638

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47638) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47637

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47637) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47635

Microsoft Outlook and Word Remote Code Execution vulnerability

Microsoft Outlook and Word Remote Code Execution vulnerability (CVE-2026-47635) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47634

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47634) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47631

Microsoft Exchange Server Spoofing vulnerability

Microsoft Exchange Server Spoofing vulnerability (CVE-2026-47631) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47293

Microsoft Office Click-To-Run Elevation of Privilege vulnerability

Microsoft Office Click-To-Run Elevation of Privilege vulnerability (CVE-2026-47293) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47288

Windows Kerberos Key Distribution Center (KDC) Remote Code Execution vulnerability

Windows Kerberos Key Distribution Center (KDC) Remote Code Execution vulnerability (CVE-2026-47288) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47287

Visual Studio Code Tampering vulnerability

Visual Studio Code Tampering vulnerability (CVE-2026-47287) was added to Microsoft’s security update guidance. Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47284

Visual Studio Code Information Disclosure vulnerability

Visual Studio Code Information Disclosure vulnerability (CVE-2026-47284) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47281

Visual Studio Code Elevation of Privilege vulnerability

Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-47281) was added to Microsoft’s security update guidance. Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45658

Windows BitLocker Security Feature Bypass vulnerability

Windows BitLocker Security Feature Bypass vulnerability (CVE-2026-45658) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45657

Windows Kernel Remote Code Execution vulnerability

Windows Kernel Remote Code Execution vulnerability (CVE-2026-45657) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45655

Windows BitLocker Security Feature Bypass vulnerability

Windows BitLocker Security Feature Bypass vulnerability (CVE-2026-45655) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45653

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-45653) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45650

Microsoft Bing Search Spoofing vulnerability

Microsoft Bing Search Spoofing vulnerability (CVE-2026-45650) was added to Microsoft’s security update guidance. User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45648

Windows Active Directory Domain Services Remote Code Execution vulnerability

Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-45648) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45647

Microsoft Defender for Endpoint for Mac Elevation of Privilege vulnerability

Microsoft Defender for Endpoint for Mac Elevation of Privilege vulnerability (CVE-2026-45647) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45644

Microsoft Live Share Canvas SDK Elevation of Privilege vulnerability

Microsoft Live Share Canvas SDK Elevation of Privilege vulnerability (CVE-2026-45644) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45642

Microsoft Azure Attestation service and Device Health Attestation Service Spoofing vulnerability

Microsoft Azure Attestation service and Device Health Attestation Service Spoofing vulnerability (CVE-2026-45642) was added to Microsoft’s security update guidance. Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45641

Windows Hyper-V Remote Code Execution vulnerability

Windows Hyper-V Remote Code Execution vulnerability (CVE-2026-45641) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45640

Windows Bluetooth Port Driver Elevation of Privilege vulnerability

Windows Bluetooth Port Driver Elevation of Privilege vulnerability (CVE-2026-45640) was added to Microsoft’s security update guidance. Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45636

Windows NTFS Remote Code Execution vulnerability

Windows NTFS Remote Code Execution vulnerability (CVE-2026-45636) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.