Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Server Elevation of Privilege vulnerability
Windows Server Elevation of Privilege vulnerability (CVE-2026-50311) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-33835) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability
Chromium CVE-2026-87559: UI misrepresentation in Microsoft Edge vulnerability (CVE-2026-87559) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85893) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-69486) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Planetary Computer Pro Elevation of Privilege vulnerability
Microsoft Planetary Computer Pro Elevation of Privilege vulnerability (CVE-2026-63508) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege vulnerability
Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege vulnerability (CVE-2026-62772) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows HTTP.sys Elevation of Privilege vulnerability
Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62753) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Message Queuing Elevation of Privilege vulnerability
Windows Message Queuing Elevation of Privilege vulnerability (CVE-2026-62717) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Display Enhancement Service Elevation of Privilege vulnerability
Windows Display Enhancement Service Elevation of Privilege vulnerability (CVE-2026-61923) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55053) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-50688) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Client Elevation of Privilege vulnerability
Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-50683) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability
Windows Audio Compression Manager (ACM) Elevation of Privilege vulnerability (CVE-2026-50351) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Secure Kernel Mode Elevation of Privilege vulnerability
Windows Secure Kernel Mode Elevation of Privilege vulnerability (CVE-2026-85921) was added to Microsoft’s security update guidance. <p>Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability
Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability (CVE-2026-62721) was added to Microsoft’s security update guidance. The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix. Microsoft recommends installing these updates as soon as possible. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-85892) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Use after free in WebGL in Microsoft Edge vulnerability
Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-84352) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Dawn in Microsoft Edge vulnerability
Use after free in Dawn in Microsoft Edge vulnerability (CVE-2026-84333) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
UI misrepresentation in FullScreen in Microsoft Edge vulnerability
UI misrepresentation in FullScreen in Microsoft Edge vulnerability (CVE-2026-84330) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Spoofing vulnerability
Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-77490) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Imaging Component Remote Code Execution vulnerability
Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-69860) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Link Layer Topology Discovery Protocol Remote Code Execution vulnerability
Windows Link Layer Topology Discovery Protocol Remote Code Execution vulnerability (CVE-2026-69732) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows SMB Client Elevation of Privilege vulnerability
Windows SMB Client Elevation of Privilege vulnerability (CVE-2026-62799) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.