Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-33823

Microsoft Team Events Portal Information Disclosure vulnerability

Microsoft Team Events Portal Information Disclosure vulnerability (CVE-2026-33823) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33821

Microsoft Dynamics 365 Customer Insights Elevation of Privilege vulnerability

Microsoft Dynamics 365 Customer Insights Elevation of Privilege vulnerability (CVE-2026-33821) was added to Microsoft’s security update guidance. Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33111

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Microsoft Copilot Chat (Microsoft Edge) Information Disclosure (CVE-2026-33111) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33109

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-33109) was added to Microsoft’s security update guidance. Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32207

Azure Machine Learning Notebook Spoofing vulnerability

Azure Machine Learning Notebook Spoofing vulnerability (CVE-2026-32207) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-3298

Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability

Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes vulnerability (CVE-2026-3298) was added to Microsoft’s security update guidance. Information published. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-21246

Windows Graphics Component Elevation of Privilege Vulnerability

Microsoft Windows Graphics Component Elevation of Privilege (CVE-2026-21246) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33103

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Microsoft Microsoft Dynamics 365 (On-Premises) Information Disclosure (CVE-2026-33103) was added to Microsoft’s security update guidance. Added acknowledgements. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-26149

Microsoft Power Apps Desktop Client Spoofing Vulnerability

Microsoft Microsoft Power Apps Desktop Client Spoofing (CVE-2026-26149) was added to Microsoft’s security update guidance. CVE-2026-26149 Microsoft Power Apps Desktop Client Spoofing Vulnerability PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-35431

Microsoft Entra ID Entitlement Management Spoofing Vulnerability

Microsoft Microsoft Entra ID Entitlement Management Spoofing (CVE-2026-35431) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33819

Microsoft Bing Remote Code Execution Vulnerability

Microsoft Microsoft Bing Remote Code Execution (CVE-2026-33819) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-33102

Microsoft 365 Copilot Elevation of Privilege Vulnerability

Microsoft Microsoft 365 Copilot Elevation of Privilege (CVE-2026-33102) was added to Microsoft’s security update guidance. Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32210

Microsoft Dynamics 365 (online) Spoofing Vulnerability

Microsoft Microsoft Dynamics 365 (online) Spoofing (CVE-2026-32210) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-32172

Microsoft Power Apps Remote Code Execution Vulnerability

Microsoft Microsoft Power Apps Remote Code Execution (CVE-2026-32172) was added to Microsoft’s security update guidance. Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-26150

Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Microsoft Microsoft Purview eDiscovery Elevation of Privilege (CVE-2026-26150) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-24303

Microsoft Partner Center Elevation of Privilege Vulnerability

Microsoft Microsoft Partner Center Elevation of Privilege (CVE-2026-24303) was added to Microsoft’s security update guidance. Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-21515

Azure IoT Central Elevation of Privilege Vulnerability

Microsoft Azure IoT Central Elevation of Privilege (CVE-2026-21515) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2026-33825

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-33825). Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. CISA remediation due date: 2026-05-06. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-32201

Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-32201). Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. CISA remediation due date: 2026-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2009-0238

Microsoft Office Remote Code Execution vulnerability

Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2009-0238). Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. CISA remediation due date: 2026-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-60710

Microsoft Windows Link Following Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-60710). Microsoft Windows contains a link following vulnerability that allows for privilege escalation CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2023-36424

Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-36424). Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-21529

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-21529). Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2012-1854

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft Visual Basic for Applications (VBA) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-1854). Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. CISA remediation due date: 2026-04-27. If you need help checking exposure, call (864) 335-9223.