Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-70283) was added to Microsoft’s security update guidance. <p>Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Media Player Remote Code Execution vulnerability
Windows Media Player Remote Code Execution vulnerability (CVE-2026-70203) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Fabric Elevation of Privilege vulnerability
Microsoft Fabric Elevation of Privilege vulnerability (CVE-2026-70178) was added to Microsoft’s security update guidance. <p>Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Information Disclosure vulnerability
Microsoft Windows Search Component Information Disclosure vulnerability (CVE-2026-70145) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Information Disclosure vulnerability
Windows DHCP Server Information Disclosure vulnerability (CVE-2026-70124) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Denial of Service vulnerability
Windows DNS Denial of Service vulnerability (CVE-2026-70091) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-70065) was added to Microsoft’s security update guidance. <p>Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Compressed Folder Information Disclosure vulnerability
Windows Compressed Folder Information Disclosure vulnerability (CVE-2026-70019) was added to Microsoft’s security update guidance. <p>Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69989) was added to Microsoft’s security update guidance. <p>Use after free in DNS Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Information Disclosure vulnerability
Windows DHCP Server Information Disclosure vulnerability (CVE-2026-69930) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Information Disclosure vulnerability
Windows DHCP Server Information Disclosure vulnerability (CVE-2026-69929) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Elevation of Privilege vulnerability
Windows Print Spooler Components Elevation of Privilege vulnerability (CVE-2026-69921) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Elevation of Privilege vulnerability
Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69911) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Remote Code Execution vulnerability
Windows Hyper-V Remote Code Execution vulnerability (CVE-2026-69910) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Enterprise App Management Elevation of Privilege vulnerability
Windows Enterprise App Management Elevation of Privilege vulnerability (CVE-2026-69907) was added to Microsoft’s security update guidance. <p>Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Secure Kernel Mode Elevation of Privilege vulnerability
Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-69906) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Information Disclosure vulnerability
Microsoft Office SharePoint Information Disclosure vulnerability (CVE-2026-69904) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Error Reporting Elevation of Privilege vulnerability
Windows Error Reporting Elevation of Privilege vulnerability (CVE-2026-69896) was added to Microsoft’s security update guidance. <p>Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Information Disclosure vulnerability
Windows Spaceport.sys Information Disclosure vulnerability (CVE-2026-69895) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Media Elevation of Privilege vulnerability
Windows Media Elevation of Privilege vulnerability (CVE-2026-69891) was added to Microsoft’s security update guidance. Use after free in Windows Media allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Virtual Trusted Platform Module Elevation of Privilege vulnerability
Windows Virtual Trusted Platform Module Elevation of Privilege vulnerability (CVE-2026-69890) was added to Microsoft’s security update guidance. <p>Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Bluetooth Service Elevation of Privilege vulnerability
Windows Bluetooth Service Elevation of Privilege vulnerability (CVE-2026-69889) was added to Microsoft’s security update guidance. Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Internet Key Exchange (IKE) Extension Denial of Service vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service vulnerability (CVE-2026-69881) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-69878) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.