Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-10984

Inappropriate implementation in Accessibility in Microsoft Edge vulnerability

Inappropriate implementation in Accessibility in Microsoft Edge vulnerability (CVE-2026-10984) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10967

Use after free in SurfaceCapture in Microsoft Edge vulnerability

Use after free in SurfaceCapture in Microsoft Edge vulnerability (CVE-2026-10967) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10959

Use after free in Input in Microsoft Edge vulnerability

Use after free in Input in Microsoft Edge vulnerability (CVE-2026-10959) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10953

Use after free in Core in Microsoft Edge vulnerability

Use after free in Core in Microsoft Edge vulnerability (CVE-2026-10953) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10934

Use after free in Autofill in Microsoft Edge vulnerability

Use after free in Autofill in Microsoft Edge vulnerability (CVE-2026-10934) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10929

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability

Heap buffer overflow in ANGLE in Microsoft Edge vulnerability (CVE-2026-10929) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10923

Use after free in WebAppInstalls in Microsoft Edge vulnerability

Use after free in WebAppInstalls in Microsoft Edge vulnerability (CVE-2026-10923) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10892

Out of bounds write in GPU in Microsoft Edge vulnerability

Out of bounds write in GPU in Microsoft Edge vulnerability (CVE-2026-10892) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-10883

Out of bounds write in ANGLE in Microsoft Edge vulnerability

Out of bounds write in ANGLE in Microsoft Edge vulnerability (CVE-2026-10883) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2025-21330

Windows Remote Desktop Services Denial of Service vulnerability

Windows Remote Desktop Services Denial of Service vulnerability (CVE-2025-21330) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2024-49132

Windows Remote Desktop Services Remote Code Execution vulnerability

Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2024-49132) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2024-49123

Windows Remote Desktop Services Remote Code Execution vulnerability

Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2024-49123) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2024-49075

Windows Remote Desktop Services Denial of Service vulnerability

Windows Remote Desktop Services Denial of Service vulnerability (CVE-2024-49075) was added to Microsoft’s security update guidance. To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2020-17103

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2020-17103) was added to Microsoft’s security update guidance. To comprehensively address the vulnerability identified by CVE-2020-17103, Microsoft recommends installing the June 2026 updates for your Windows operating systems. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-35429

Microsoft Edge (Chromium-based) for Android Spoofing vulnerability

Microsoft Edge (Chromium-based) for Android Spoofing vulnerability (CVE-2026-35429) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-33841

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-33841) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48579

Microsoft Exchange Online Information Disclosure vulnerability

Microsoft Exchange Online Information Disclosure vulnerability (CVE-2026-48579) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48567

Azure HorizonDB Elevation of Privilege vulnerability

Azure HorizonDB Elevation of Privilege vulnerability (CVE-2026-48567) was added to Microsoft’s security update guidance. Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47655

Microsoft Graph Information Disclosure vulnerability

Microsoft Graph Information Disclosure vulnerability (CVE-2026-47655) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-47644

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-47644) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-45497

Microsoft M365 Copilot Remote Code Execution vulnerability

Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-45497) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-40361

Microsoft Outlook and Word Remote Code Execution vulnerability

Microsoft Outlook and Word Remote Code Execution vulnerability (CVE-2026-40361) was added to Microsoft’s security update guidance. Updated CVE title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-45495) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45494

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-45494) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.