Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-69876) was added to Microsoft’s security update guidance. Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69875) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows ALPC Elevation of Privilege vulnerability
Windows ALPC Elevation of Privilege vulnerability (CVE-2026-69874) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69866) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hello Elevation of Privilege vulnerability
Windows Hello Elevation of Privilege vulnerability (CVE-2026-69864) was added to Microsoft’s security update guidance. <p>Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Wireless Wide Area Network Service Information Disclosure vulnerability
Windows Wireless Wide Area Network Service Information Disclosure vulnerability (CVE-2026-69862) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69859) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69858) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Cosmos DB Spoofing vulnerability
Azure Cosmos DB Spoofing vulnerability (CVE-2026-69857) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-69852) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-69847) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Windows Secure Kernel Mode Elevation of Privilege vulnerability
Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-69846) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-69845) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69844) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Encrypting File System (EFS) Elevation of Privilege vulnerability
Windows Encrypting File System (EFS) Elevation of Privilege vulnerability (CVE-2026-69841) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Target Service Denial of Service vulnerability
Windows iSCSI Target Service Denial of Service vulnerability (CVE-2026-69839) was added to Microsoft’s security update guidance. <p>Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Elevation of Privilege vulnerability
Windows Print Spooler Components Elevation of Privilege vulnerability (CVE-2026-69838) was added to Microsoft’s security update guidance. <p>Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows ALPC Elevation of Privilege vulnerability
Windows ALPC Elevation of Privilege vulnerability (CVE-2026-69834) was added to Microsoft’s security update guidance. <p>Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Shell Remote Code Execution vulnerability
Windows Shell Remote Code Execution vulnerability (CVE-2026-69829) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69827) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69826) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Remote Code Execution vulnerability
Microsoft Standard XPS Remote Code Execution vulnerability (CVE-2026-69824) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Elevation of Privilege vulnerability
Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-69822) was added to Microsoft’s security update guidance. <p>Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hello Elevation of Privilege vulnerability
Windows Hello Elevation of Privilege vulnerability (CVE-2026-69820) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.