Microsoft security briefs
3328 published alerts for Microsoft products and services.
Inappropriate implementation in Accessibility in Microsoft Edge vulnerability
Inappropriate implementation in Accessibility in Microsoft Edge vulnerability (CVE-2026-10984) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in SurfaceCapture in Microsoft Edge vulnerability
Use after free in SurfaceCapture in Microsoft Edge vulnerability (CVE-2026-10967) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Input in Microsoft Edge vulnerability
Use after free in Input in Microsoft Edge vulnerability (CVE-2026-10959) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Core in Microsoft Edge vulnerability
Use after free in Core in Microsoft Edge vulnerability (CVE-2026-10953) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Autofill in Microsoft Edge vulnerability
Use after free in Autofill in Microsoft Edge vulnerability (CVE-2026-10934) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Heap buffer overflow in ANGLE in Microsoft Edge vulnerability
Heap buffer overflow in ANGLE in Microsoft Edge vulnerability (CVE-2026-10929) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in WebAppInstalls in Microsoft Edge vulnerability
Use after free in WebAppInstalls in Microsoft Edge vulnerability (CVE-2026-10923) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds write in GPU in Microsoft Edge vulnerability
Out of bounds write in GPU in Microsoft Edge vulnerability (CVE-2026-10892) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds write in ANGLE in Microsoft Edge vulnerability
Out of bounds write in ANGLE in Microsoft Edge vulnerability (CVE-2026-10883) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Denial of Service vulnerability
Windows Remote Desktop Services Denial of Service vulnerability (CVE-2025-21330) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Remote Code Execution vulnerability
Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2024-49132) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Remote Code Execution vulnerability
Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2024-49123) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Denial of Service vulnerability
Windows Remote Desktop Services Denial of Service vulnerability (CVE-2024-49075) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2020-17103) was added to Microsoft’s security update guidance. To comprehensively address the vulnerability identified by CVE-2020-17103, Microsoft recommends installing the June 2026 updates for your Windows operating systems. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) for Android Spoofing vulnerability
Microsoft Edge (Chromium-based) for Android Spoofing vulnerability (CVE-2026-35429) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-33841) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Online Information Disclosure vulnerability
Microsoft Exchange Online Information Disclosure vulnerability (CVE-2026-48579) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Azure HorizonDB Elevation of Privilege vulnerability
Azure HorizonDB Elevation of Privilege vulnerability (CVE-2026-48567) was added to Microsoft’s security update guidance. Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Graph Information Disclosure vulnerability
Microsoft Graph Information Disclosure vulnerability (CVE-2026-47655) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-47644) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft M365 Copilot Remote Code Execution vulnerability
Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-45497) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Outlook and Word Remote Code Execution vulnerability
Microsoft Outlook and Word Remote Code Execution vulnerability (CVE-2026-40361) was added to Microsoft’s security update guidance. Updated CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-45495) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Spoofing vulnerability
Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-45494) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.