Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-41100

Microsoft 365 Copilot for Android Spoofing vulnerability

Microsoft 365 Copilot for Android Spoofing vulnerability (CVE-2026-41100) was added to Microsoft’s security update guidance. Added Microsoft Excel for Android, Microsoft Word for Android, Microsoft Loop for Android, Microsoft PowerPoint for Android and Microsoft OneNote for Android softwares to the Security Updates table. Customers that are running supported version of these products are encouraged… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41098

Azure Stack Edge Spoofing vulnerability

Azure Stack Edge Spoofing vulnerability (CVE-2026-41098) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-41092

Microsoft Kinect Elevation of Privilege vulnerability

Microsoft Kinect Elevation of Privilege vulnerability (CVE-2026-41092) was added to Microsoft’s security update guidance. Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40409

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability (CVE-2026-40409) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40404

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability (CVE-2026-40404) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-34335

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-34335) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-33828

Windows Device Health Attestation (DHA) Elevation of Privilege vulnerability

Windows Device Health Attestation (DHA) Elevation of Privilege vulnerability (CVE-2026-33828) was added to Microsoft’s security update guidance. Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-33113

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-33113) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-32193

Azure Kubernetes Service (AKS) Remote Code Execution vulnerability

Azure Kubernetes Service (AKS) Remote Code Execution vulnerability (CVE-2026-32193) was added to Microsoft’s security update guidance. Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-21530

Windows Rich Text Edit Elevation of Privilege vulnerability

Windows Rich Text Edit Elevation of Privilege vulnerability (CVE-2026-21530) was added to Microsoft’s security update guidance. Added Office softwares to the Security Updates table. Customers that are running supported versions of Office are encouraged to update to the indicated versions to be protected from this vulnerability. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11297

Insufficient validation of untrusted input in Reader Mode in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Reader Mode in Microsoft Edge vulnerability (CVE-2026-11297) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11295

Inappropriate implementation in WebView in Microsoft Edge vulnerability

Inappropriate implementation in WebView in Microsoft Edge vulnerability (CVE-2026-11295) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11291

Policy bypass in Android Autofill in Microsoft Edge vulnerability

Policy bypass in Android Autofill in Microsoft Edge vulnerability (CVE-2026-11291) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11290

Integer overflow in WebView in Microsoft Edge vulnerability

Integer overflow in WebView in Microsoft Edge vulnerability (CVE-2026-11290) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11287

Insufficient validation of untrusted input in Navigation in Microsoft Edge vulnerability

Insufficient validation of untrusted input in Navigation in Microsoft Edge vulnerability (CVE-2026-11287) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11278

Inappropriate implementation in CustomTabs in Microsoft Edge vulnerability

Inappropriate implementation in CustomTabs in Microsoft Edge vulnerability (CVE-2026-11278) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11270

Inappropriate implementation in Microsoft Edge vulnerability

Inappropriate implementation in Microsoft Edge vulnerability (CVE-2026-11270) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11263

Insufficient policy enforcement in WebAuthentication in Microsoft Edge vulnerability

Insufficient policy enforcement in WebAuthentication in Microsoft Edge vulnerability (CVE-2026-11263) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11247

Insufficient policy enforcement in CustomTabs in Microsoft Edge vulnerability

Insufficient policy enforcement in CustomTabs in Microsoft Edge vulnerability (CVE-2026-11247) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11226

Insufficient policy enforcement in PreviewTab in Microsoft Edge vulnerability

Insufficient policy enforcement in PreviewTab in Microsoft Edge vulnerability (CVE-2026-11226) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11215

Inappropriate implementation in Cronet in Microsoft Edge vulnerability

Inappropriate implementation in Cronet in Microsoft Edge vulnerability (CVE-2026-11215) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11188

Use after free in USB in Microsoft Edge vulnerability

Use after free in USB in Microsoft Edge vulnerability (CVE-2026-11188) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11178

Policy bypass in WebView in Microsoft Edge vulnerability

Policy bypass in WebView in Microsoft Edge vulnerability (CVE-2026-11178) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-11175

Incorrect security UI in Messages in Microsoft Edge vulnerability

Incorrect security UI in Messages in Microsoft Edge vulnerability (CVE-2026-11175) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.