Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Failover Cluster Information Disclosure vulnerability
Windows Failover Cluster Information Disclosure vulnerability (CVE-2026-72989) was added to Microsoft’s security update guidance. <p>Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-72988) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Remote Code Execution vulnerability
Windows DNS Remote Code Execution vulnerability (CVE-2026-72987) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Netlogon Remote Code Execution vulnerability
Windows Netlogon Remote Code Execution vulnerability (CVE-2026-72982) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hello Security Feature Bypass vulnerability
Windows Hello Security Feature Bypass vulnerability (CVE-2026-72980) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-72979) was added to Microsoft’s security update guidance. <p>Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office PowerPoint Information Disclosure vulnerability
Microsoft Office PowerPoint Information Disclosure vulnerability (CVE-2026-72977) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Information Disclosure vulnerability
Microsoft Office Word Information Disclosure vulnerability (CVE-2026-72976) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Office PowerPoint Information Disclosure vulnerability
Microsoft Office PowerPoint Information Disclosure vulnerability (CVE-2026-72975) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Office Excel Information Disclosure vulnerability
Microsoft Office Excel Information Disclosure vulnerability (CVE-2026-72974) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-72973) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-72972) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Network Connection Broker Elevation of Privilege vulnerability
Windows Network Connection Broker Elevation of Privilege vulnerability (CVE-2026-72967) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Remote Access Connection Manager Tampering vulnerability
Windows Remote Access Connection Manager Tampering vulnerability (CVE-2026-72966) was added to Microsoft’s security update guidance. <p>Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows WebClient Service Elevation of Privilege vulnerability
Windows WebClient Service Elevation of Privilege vulnerability (CVE-2026-72965) was added to Microsoft’s security update guidance. <p>Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Internet Connection Sharing (ICS) Tampering vulnerability
Windows Internet Connection Sharing (ICS) Tampering vulnerability (CVE-2026-72964) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Modern Execution Server Elevation of Privilege vulnerability
Windows Modern Execution Server Elevation of Privilege vulnerability (CVE-2026-72963) was added to Microsoft’s security update guidance. <p>Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Video Driver Elevation of Privilege vulnerability
Windows USB Video Driver Elevation of Privilege vulnerability (CVE-2026-72962) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Elevation of Privilege vulnerability
Windows Hyper-V Elevation of Privilege vulnerability (CVE-2026-72961) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Media Player Remote Code Execution vulnerability
Windows Media Player Remote Code Execution vulnerability (CVE-2026-72960) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-72959) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.
Windows Credential Guard Elevation of Privilege vulnerability
Windows Credential Guard Elevation of Privilege vulnerability (CVE-2026-72958) was added to Microsoft’s security update guidance. <p>Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Deployment Services Remote Code Execution vulnerability
Windows Deployment Services Remote Code Execution vulnerability (CVE-2026-72957) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office PowerPoint Information Disclosure vulnerability
Microsoft Office PowerPoint Information Disclosure vulnerability (CVE-2026-72956) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.