Microsoft security briefs
3328 published alerts for Microsoft products and services.
Microsoft Office Spoofing vulnerability
Microsoft Office Spoofing vulnerability (CVE-2026-42832) was added to Microsoft’s security update guidance. Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-42831) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Monitor Agent Metrics Extension Elevation of Privilege vulnerability
Azure Monitor Agent Metrics Extension Elevation of Privilege vulnerability (CVE-2026-42830) was added to Microsoft’s security update guidance. Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Logic Apps Elevation of Privilege vulnerability
Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-42823) was added to Microsoft’s security update guidance. Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Visual Studio Code Elevation of Privilege vulnerability
Visual Studio Code Elevation of Privilege vulnerability (CVE-2026-41613) was added to Microsoft’s security update guidance. Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Visual Studio Code Information Disclosure vulnerability
Visual Studio Code Information Disclosure vulnerability (CVE-2026-41612) was added to Microsoft’s security update guidance. Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Visual Studio Code Remote Code Execution vulnerability
Visual Studio Code Remote Code Execution vulnerability (CVE-2026-41611) was added to Microsoft’s security update guidance. Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-41610) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege vulnerability
Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege vulnerability (CVE-2026-41103) was added to Microsoft’s security update guidance. Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft PowerPoint for Android Spoofing vulnerability
Microsoft PowerPoint for Android Spoofing vulnerability (CVE-2026-41102) was added to Microsoft’s security update guidance. Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Word for Android Spoofing vulnerability
Microsoft Word for Android Spoofing vulnerability (CVE-2026-41101) was added to Microsoft’s security update guidance. Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows DNS Client Remote Code Execution vulnerability
Windows DNS Client Remote Code Execution vulnerability (CVE-2026-41096) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Data Formulator Remote Code Execution vulnerability
Microsoft Data Formulator Remote Code Execution vulnerability (CVE-2026-41094) was added to Microsoft’s security update guidance. Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Netlogon Remote Code Execution vulnerability
Windows Netlogon Remote Code Execution vulnerability (CVE-2026-41089) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Word Information Disclosure vulnerability
Microsoft Word Information Disclosure vulnerability (CVE-2026-40421) was added to Microsoft’s security update guidance. External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Click-To-Run Elevation of Privilege vulnerability
Microsoft Office Click-To-Run Elevation of Privilege vulnerability (CVE-2026-40420) was added to Microsoft’s security update guidance. Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Click-To-Run Elevation of Privilege vulnerability
Microsoft Office Click-To-Run Elevation of Privilege vulnerability (CVE-2026-40419) was added to Microsoft’s security update guidance. Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Click-To-Run Elevation of Privilege vulnerability
Microsoft Office Click-To-Run Elevation of Privilege vulnerability (CVE-2026-40418) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Remote Code Execution vulnerability
Windows TCP/IP Remote Code Execution vulnerability (CVE-2026-40415) was added to Microsoft’s security update guidance. Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Denial of Service vulnerability
Windows TCP/IP Denial of Service vulnerability (CVE-2026-40414) was added to Microsoft’s security update guidance. Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Denial of Service vulnerability
Windows TCP/IP Denial of Service vulnerability (CVE-2026-40413) was added to Microsoft’s security update guidance. Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows SMB Client Elevation of Privilege vulnerability
Windows SMB Client Elevation of Privilege vulnerability (CVE-2026-40410) was added to Microsoft’s security update guidance. Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows WAN ARP Driver Elevation of Privilege vulnerability
Windows WAN ARP Driver Elevation of Privilege vulnerability (CVE-2026-40408) was added to Microsoft’s security update guidance. Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Common Log File System Driver Elevation of Privilege vulnerability
Windows Common Log File System Driver Elevation of Privilege vulnerability (CVE-2026-40407) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.