Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-34338

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-34338) was added to Microsoft’s security update guidance. Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34337

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-34337) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34334

Windows TCP/IP Elevation of Privilege vulnerability

Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-34334) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34333

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-34333) was added to Microsoft’s security update guidance. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34332

Windows Kernel-Mode Driver Remote Code Execution vulnerability

Windows Kernel-Mode Driver Remote Code Execution vulnerability (CVE-2026-34332) was added to Microsoft’s security update guidance. Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-34329

Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability

Microsoft Message Queuing (MSMQ) Remote Code Execution vulnerability (CVE-2026-34329) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33838

Windows Message Queuing (MSMQ) Elevation of Privilege vulnerability

Windows Message Queuing (MSMQ) Elevation of Privilege vulnerability (CVE-2026-33838) was added to Microsoft’s security update guidance. Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33837

Windows TCP/IP Local Elevation of Privilege vulnerability

Windows TCP/IP Local Elevation of Privilege vulnerability (CVE-2026-33837) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33834

Windows Event Logging Service Elevation of Privilege vulnerability

Windows Event Logging Service Elevation of Privilege vulnerability (CVE-2026-33834) was added to Microsoft’s security update guidance. Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33833

Azure Machine Learning Notebook Spoofing vulnerability

Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-33833) was added to Microsoft’s security update guidance. Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33112

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33112) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33110

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-33110) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32209

Windows Filtering Platform (WFP) Security Feature Bypass vulnerability

Windows Filtering Platform (WFP) Security Feature Bypass vulnerability (CVE-2026-32209) was added to Microsoft’s security update guidance. Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32204

Azure Monitor Agent Elevation of Privilege vulnerability

Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-32204) was added to Microsoft’s security update guidance. External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2026-20841

Windows Notepad App Remote Code Execution vulnerability

Windows Notepad App Remote Code Execution vulnerability (CVE-2026-20841) was added to Microsoft’s security update guidance. Added FAQ information. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-8021

UI vulnerability

UI vulnerability (CVE-2026-8021) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-7992

UI vulnerability

UI vulnerability (CVE-2026-7992) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-7991

UI vulnerability

UI vulnerability (CVE-2026-7991) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026 ) for more information. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-42826

Azure DevOps Information Disclosure vulnerability

Azure DevOps Information Disclosure vulnerability (CVE-2026-42826) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-41105

Azure Monitor Action Group Notification System Elevation of Privilege vulnerability

Azure Monitor Action Group Notification System Elevation of Privilege vulnerability (CVE-2026-41105) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35435

Azure AI Foundry Elevation of Privilege vulnerability

Azure AI Foundry Elevation of Privilege vulnerability (CVE-2026-35435) was added to Microsoft’s security update guidance. Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35428

Azure Cloud Shell Spoofing vulnerability

Azure Cloud Shell Spoofing vulnerability (CVE-2026-35428) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

HighMicrosoft MSRC

CVE-2026-34327

Microsoft Partner Center Spoofing vulnerability

Microsoft Partner Center Spoofing vulnerability (CVE-2026-34327) was added to Microsoft’s security update guidance. Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

CriticalMicrosoft MSRC

CVE-2026-33844

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-33844) was added to Microsoft’s security update guidance. Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.