Microsoft security briefs
3328 published alerts for Microsoft products and services.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-34338) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-34337) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-34334) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-34333) was added to Microsoft’s security update guidance. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Kernel-Mode Driver Remote Code Execution vulnerability
Windows Kernel-Mode Driver Remote Code Execution vulnerability (CVE-2026-34332) was added to Microsoft’s security update guidance. Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability (CVE-2026-34329) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Message Queuing (MSMQ) Elevation of Privilege vulnerability
Windows Message Queuing (MSMQ) Elevation of Privilege vulnerability (CVE-2026-33838) was added to Microsoft’s security update guidance. Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows TCP/IP Local Elevation of Privilege vulnerability
Windows TCP/IP Local Elevation of Privilege vulnerability (CVE-2026-33837) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Event Logging Service Elevation of Privilege vulnerability
Windows Event Logging Service Elevation of Privilege vulnerability (CVE-2026-33834) was added to Microsoft’s security update guidance. Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Machine Learning Notebook Spoofing vulnerability
Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-33833) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33112) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33110) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Filtering Platform (WFP) Security Feature Bypass vulnerability
Windows Filtering Platform (WFP) Security Feature Bypass vulnerability (CVE-2026-32209) was added to Microsoft’s security update guidance. Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Monitor Agent Elevation of Privilege vulnerability
Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-32204) was added to Microsoft’s security update guidance. External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Notepad App Remote Code Execution vulnerability
Windows Notepad App Remote Code Execution vulnerability (CVE-2026-20841) was added to Microsoft’s security update guidance. Added FAQ information. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
UI vulnerability
UI vulnerability (CVE-2026-8021) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
UI vulnerability
UI vulnerability (CVE-2026-7992) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
UI vulnerability
UI vulnerability (CVE-2026-7991) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure DevOps Information Disclosure vulnerability
Azure DevOps Information Disclosure vulnerability (CVE-2026-42826) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Monitor Action Group Notification System Elevation of Privilege vulnerability
Azure Monitor Action Group Notification System Elevation of Privilege vulnerability (CVE-2026-41105) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure AI Foundry Elevation of Privilege vulnerability
Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-35435) was added to Microsoft’s security update guidance. Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Cloud Shell Spoofing vulnerability
Azure Cloud Shell Spoofing vulnerability (CVE-2026-35428) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Partner Center Spoofing vulnerability
Microsoft Partner Center Spoofing vulnerability (CVE-2026-34327) was added to Microsoft’s security update guidance. Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-33844) was added to Microsoft’s security update guidance. Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.