Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-72989

Windows Failover Cluster Information Disclosure vulnerability

Windows Failover Cluster Information Disclosure vulnerability (CVE-2026-72989) was added to Microsoft’s security update guidance. <p>Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72988

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-72988) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72987

Windows DNS Remote Code Execution vulnerability

Windows DNS Remote Code Execution vulnerability (CVE-2026-72987) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72982

Windows Netlogon Remote Code Execution vulnerability

Windows Netlogon Remote Code Execution vulnerability (CVE-2026-72982) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72980

Windows Hello Security Feature Bypass vulnerability

Windows Hello Security Feature Bypass vulnerability (CVE-2026-72980) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72979

Windows DHCP Server Remote Code Execution vulnerability

Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-72979) was added to Microsoft’s security update guidance. <p>Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72977

Microsoft Office PowerPoint Information Disclosure vulnerability

Microsoft Office PowerPoint Information Disclosure vulnerability (CVE-2026-72977) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72976

Microsoft Office Word Information Disclosure vulnerability

Microsoft Office Word Information Disclosure vulnerability (CVE-2026-72976) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72975

Microsoft Office PowerPoint Information Disclosure vulnerability

Microsoft Office PowerPoint Information Disclosure vulnerability (CVE-2026-72975) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72974

Microsoft Office Excel Information Disclosure vulnerability

Microsoft Office Excel Information Disclosure vulnerability (CVE-2026-72974) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72973

Microsoft Office Word Remote Code Execution vulnerability

Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-72973) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72972

Microsoft Office Word Remote Code Execution vulnerability

Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-72972) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72967

Windows Network Connection Broker Elevation of Privilege vulnerability

Windows Network Connection Broker Elevation of Privilege vulnerability (CVE-2026-72967) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72966

Windows Remote Access Connection Manager Tampering vulnerability

Windows Remote Access Connection Manager Tampering vulnerability (CVE-2026-72966) was added to Microsoft’s security update guidance. <p>Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72965

Windows WebClient Service Elevation of Privilege vulnerability

Windows WebClient Service Elevation of Privilege vulnerability (CVE-2026-72965) was added to Microsoft’s security update guidance. <p>Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72964

Windows Internet Connection Sharing (ICS) Tampering vulnerability

Windows Internet Connection Sharing (ICS) Tampering vulnerability (CVE-2026-72964) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72963

Windows Modern Execution Server Elevation of Privilege vulnerability

Windows Modern Execution Server Elevation of Privilege vulnerability (CVE-2026-72963) was added to Microsoft’s security update guidance. <p>Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72962

Windows USB Video Driver Elevation of Privilege vulnerability

Windows USB Video Driver Elevation of Privilege vulnerability (CVE-2026-72962) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72961

Windows Hyper-V Elevation of Privilege vulnerability

Windows Hyper-V Elevation of Privilege vulnerability (CVE-2026-72961) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72960

Windows Media Player Remote Code Execution vulnerability

Windows Media Player Remote Code Execution vulnerability (CVE-2026-72960) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72959

Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability

Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-72959) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72958

Windows Credential Guard Elevation of Privilege vulnerability

Windows Credential Guard Elevation of Privilege vulnerability (CVE-2026-72958) was added to Microsoft’s security update guidance. <p>Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72957

Windows Deployment Services Remote Code Execution vulnerability

Windows Deployment Services Remote Code Execution vulnerability (CVE-2026-72957) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-72956

Microsoft Office PowerPoint Information Disclosure vulnerability

Microsoft Office PowerPoint Information Disclosure vulnerability (CVE-2026-72956) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.