Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-50311

Windows Server Elevation of Privilege vulnerability

Windows Server Elevation of Privilege vulnerability (CVE-2026-50311) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-33835

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-33835) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-87559

Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability

Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability (CVE-2026-87559) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-85893

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85893) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-69486

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-69486) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63508

Microsoft Planetary Computer Pro Elevation of Privilege vulnerability

Microsoft Planetary Computer Pro Elevation of Privilege vulnerability (CVE-2026-63508) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62772

Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege vulnerability

Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege vulnerability (CVE-2026-62772) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62753

Windows HTTP.sys Elevation of Privilege vulnerability

Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62753) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62717

Windows Message Queuing Elevation of Privilege vulnerability

Windows Message Queuing Elevation of Privilege vulnerability (CVE-2026-62717) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61923

Windows Display Enhancement Service Elevation of Privilege vulnerability

Windows Display Enhancement Service Elevation of Privilege vulnerability (CVE-2026-61923) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55053

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55053) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50688

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-50688) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50683

Windows DHCP Client Elevation of Privilege vulnerability

Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-50683) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50351

Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability

Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability (CVE-2026-50351) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-85921

Windows Secure Kernel Mode Elevation of Privilege vulnerability

Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-85921) was added to Microsoft’s security update guidance. <p>Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62721

Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability

Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability (CVE-2026-62721) was added to Microsoft’s security update guidance. The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix. Microsoft recommends installing these updates as soon as possible. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85892

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85892) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-84352

Use after free in WebGL in Microsoft Edge vulnerability

Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-84352) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

CriticalMicrosoft MSRC

CVE-2026-84333

Use after free in Dawn in Microsoft Edge vulnerability

Use after free in Dawn in Microsoft Edge vulnerability (CVE-2026-84333) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-84330

UI misrepresentation in FullScreen in Microsoft Edge vulnerability

UI misrepresentation in FullScreen in Microsoft Edge vulnerability (CVE-2026-84330) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-77490

Microsoft Edge (Chromium-based) Spoofing vulnerability

Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-77490) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69860

Windows Imaging Component Remote Code Execution vulnerability

Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-69860) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69732

Windows Link Layer Topology Discovery Protocol Remote Code Execution vulnerability

Windows Link Layer Topology Discovery Protocol Remote Code Execution vulnerability (CVE-2026-69732) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62799

Windows SMB Client Elevation of Privilege vulnerability

Windows SMB Client Elevation of Privilege vulnerability (CVE-2026-62799) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.