Microsoft security briefs
3328 published alerts for Microsoft products and services.
Windows TCP/IP Information Disclosure vulnerability
Windows TCP/IP Information Disclosure vulnerability (CVE-2026-40406) was added to Microsoft’s security update guidance. Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Denial of Service vulnerability
Windows TCP/IP Denial of Service vulnerability (CVE-2026-40405) was added to Microsoft’s security update guidance. Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Graphics Component Remote Code Execution vulnerability
Windows Graphics Component Remote Code Execution vulnerability (CVE-2026-40403) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Hyper-V Elevation of Privilege vulnerability
Windows Hyper-V Elevation of Privilege vulnerability (CVE-2026-40402) was added to Microsoft’s security update guidance. Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Denial of Service vulnerability
Windows TCP/IP Denial of Service vulnerability (CVE-2026-40401) was added to Microsoft’s security update guidance. Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-40399) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-40398) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Common Log File System Driver Elevation of Privilege vulnerability
Windows Common Log File System Driver Elevation of Privilege vulnerability (CVE-2026-40397) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-40382) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Connected Machine Agent Elevation of Privilege vulnerability
Azure Connected Machine Agent Elevation of Privilege vulnerability (CVE-2026-40381) was added to Microsoft’s security update guidance. Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Volume Manager Extension Driver Remote Code Execution vulnerability
Windows Volume Manager Extension Driver Remote Code Execution vulnerability (CVE-2026-40380) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Cryptographic Services Elevation of Privilege vulnerability
Microsoft Cryptographic Services Elevation of Privilege vulnerability (CVE-2026-40377) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Power Automate Desktop Information Disclosure vulnerability
Microsoft Power Automate Desktop Information Disclosure vulnerability (CVE-2026-40374) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
SQL Server Remote Code Execution vulnerability
SQL Server Remote Code Execution vulnerability (CVE-2026-40370) was added to Microsoft’s security update guidance. External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-40369) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-40368) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-40366) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-40365) was added to Microsoft’s security update guidance. Insufficient granularity of access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-40364) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-40363) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-40362) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Excel Information Disclosure vulnerability
Microsoft Excel Information Disclosure vulnerability (CVE-2026-40360) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-40359) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-40358) was added to Microsoft’s security update guidance. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.