Microsoft security briefs
3328 published alerts for Microsoft products and services.
Microsoft Team Events Portal Information Disclosure vulnerability
Microsoft Team Events Portal Information Disclosure vulnerability (CVE-2026-33823) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Dynamics 365 Customer Insights Elevation of Privilege vulnerability
Microsoft Dynamics 365 Customer Insights Elevation of Privilege vulnerability (CVE-2026-33821) was added to Microsoft’s security update guidance. Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-33111) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-33109) was added to Microsoft’s security update guidance. Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Machine Learning Notebook Spoofing vulnerability
Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-32207) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability
Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability (CVE-2026-3298) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Graphics Component Elevation of Privilege Vulnerability
Microsoft Windows Graphics Component Elevation of Privilege (CVE-2026-21246) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Microsoft Dynamics 365 (On-Premises) Information Disclosure (CVE-2026-33103) was added to Microsoft’s security update guidance. Added acknowledgements. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Power Apps Desktop Client Spoofing Vulnerability
Microsoft Microsoft Power Apps Desktop Client Spoofing (CVE-2026-26149) was added to Microsoft’s security update guidance. CVE-2026-26149 Microsoft Power Apps Desktop Client Spoofing Vulnerability PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Entra ID Entitlement Management Spoofing Vulnerability
Microsoft Microsoft Entra ID Entitlement Management Spoofing (CVE-2026-35431) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Bing Remote Code Execution Vulnerability
Microsoft Microsoft Bing Remote Code Execution (CVE-2026-33819) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft 365 Copilot Elevation of Privilege Vulnerability
Microsoft Microsoft 365 Copilot Elevation of Privilege (CVE-2026-33102) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Dynamics 365 (online) Spoofing Vulnerability
Microsoft Microsoft Dynamics 365 (online) Spoofing (CVE-2026-32210) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Power Apps Remote Code Execution Vulnerability
Microsoft Microsoft Power Apps Remote Code Execution (CVE-2026-32172) was added to Microsoft’s security update guidance. Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
Microsoft Microsoft Purview eDiscovery Elevation of Privilege (CVE-2026-26150) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Partner Center Elevation of Privilege Vulnerability
Microsoft Microsoft Partner Center Elevation of Privilege (CVE-2026-24303) was added to Microsoft’s security update guidance. Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure IoT Central Elevation of Privilege Vulnerability
Microsoft Azure IoT Central Elevation of Privilege (CVE-2026-21515) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-33825). Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. CISA remediation due date: 2026-05-06. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Improper Input Validation Vulnerability
Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-32201). Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. CISA remediation due date: 2026-04-28. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-0238). Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. CISA remediation due date: 2026-04-28. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Link Following Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-60710). Microsoft Windows contains a link following vulnerability that allows for privilege escalation CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Out-of-Bounds Read Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-36424). Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-21529). Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
Microsoft Visual Basic for Applications (VBA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1854). Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.