Microsoft security briefs
3328 published alerts for Microsoft products and services.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47640) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47639) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47638) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47637) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Outlook and Word Remote Code Execution vulnerability
Microsoft Outlook and Word Remote Code Execution vulnerability (CVE-2026-47635) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-47634) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Spoofing vulnerability
Microsoft Exchange Server Spoofing vulnerability (CVE-2026-47631) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Click-To-Run Elevation of Privilege vulnerability
Microsoft Office Click-To-Run Elevation of Privilege vulnerability (CVE-2026-47293) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Key Distribution Center (KDC) Remote Code Execution vulnerability
Windows Kerberos Key Distribution Center (KDC) Remote Code Execution vulnerability (CVE-2026-47288) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Tampering vulnerability
Visual Studio Code Tampering vulnerability (CVE-2026-47287) was added to Microsoft’s security update guidance. Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Information Disclosure vulnerability
Visual Studio Code Information Disclosure vulnerability (CVE-2026-47284) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Elevation of Privilege vulnerability
Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-47281) was added to Microsoft’s security update guidance. Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows BitLocker Security Feature Bypass vulnerability
Windows BitLocker Security Feature Bypass vulnerability (CVE-2026-45658) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Remote Code Execution vulnerability
Windows Kernel Remote Code Execution vulnerability (CVE-2026-45657) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows BitLocker Security Feature Bypass vulnerability
Windows BitLocker Security Feature Bypass vulnerability (CVE-2026-45655) was added to Microsoft’s security update guidance. Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-45653) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Bing Search Spoofing vulnerability
Microsoft Bing Search Spoofing vulnerability (CVE-2026-45650) was added to Microsoft’s security update guidance. User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Domain Services Remote Code Execution vulnerability
Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-45648) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender for Endpoint for Mac Elevation of Privilege vulnerability
Microsoft Defender for Endpoint for Mac Elevation of Privilege vulnerability (CVE-2026-45647) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Live Share Canvas SDK Elevation of Privilege vulnerability
Microsoft Live Share Canvas SDK Elevation of Privilege vulnerability (CVE-2026-45644) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Azure Attestation service and Device Health Attestation Service Spoofing vulnerability
Microsoft Azure Attestation service and Device Health Attestation Service Spoofing vulnerability (CVE-2026-45642) was added to Microsoft’s security update guidance. Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Remote Code Execution vulnerability
Windows Hyper-V Remote Code Execution vulnerability (CVE-2026-45641) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Bluetooth Port Driver Elevation of Privilege vulnerability
Windows Bluetooth Port Driver Elevation of Privilege vulnerability (CVE-2026-45640) was added to Microsoft’s security update guidance. Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-45636) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.