Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69818) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Bluetooth Port Driver Elevation of Privilege vulnerability
Windows Bluetooth Port Driver Elevation of Privilege vulnerability (CVE-2026-69817) was added to Microsoft’s security update guidance. Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Accounts Control Elevation of Privilege vulnerability
Windows Accounts Control Elevation of Privilege vulnerability (CVE-2026-69816) was added to Microsoft’s security update guidance. <p>Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Credential Providers Elevation of Privilege vulnerability
Windows Credential Providers Elevation of Privilege vulnerability (CVE-2026-69814) was added to Microsoft’s security update guidance. Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69813) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Domain Services Denial of Service vulnerability
Windows Active Directory Domain Services Denial of Service vulnerability (CVE-2026-69809) was added to Microsoft’s security update guidance. Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Remote Code Execution vulnerability
Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69804) was added to Microsoft’s security update guidance. <p>Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Information Disclosure vulnerability
Windows DHCP Server Information Disclosure vulnerability (CVE-2026-69803) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Audio Service Elevation of Privilege vulnerability
Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-69801) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Hello Elevation of Privilege vulnerability
Windows Hello Elevation of Privilege vulnerability (CVE-2026-69799) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office PowerPoint Remote Code Execution vulnerability
Microsoft Office PowerPoint Remote Code Execution vulnerability (CVE-2026-69797) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Encrypting File System (EFS) Information Disclosure vulnerability
Windows Encrypting File System (EFS) Information Disclosure vulnerability (CVE-2026-69794) was added to Microsoft’s security update guidance. Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Security Feature Bypass vulnerability
Windows TCP/IP Security Feature Bypass vulnerability (CVE-2026-69793) was added to Microsoft’s security update guidance. Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.
Windows Win32K Security Feature Bypass vulnerability
Windows Win32K Security Feature Bypass vulnerability (CVE-2026-69792) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69791) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Credential Providers Elevation of Privilege vulnerability
Windows Credential Providers Elevation of Privilege vulnerability (CVE-2026-69790) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69787) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Text Shaping Remote Code Execution vulnerability
Windows Text Shaping Remote Code Execution vulnerability (CVE-2026-69786) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Smart Card Elevation of Privilege vulnerability
Windows Smart Card Elevation of Privilege vulnerability (CVE-2026-69785) was added to Microsoft’s security update guidance. Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Hello Elevation of Privilege vulnerability
Windows Hello Elevation of Privilege vulnerability (CVE-2026-69784) was added to Microsoft’s security update guidance. <p>Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69782) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Client Denial of Service vulnerability
Windows DHCP Client Denial of Service vulnerability (CVE-2026-69781) was added to Microsoft’s security update guidance. <p>Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69779) was added to Microsoft’s security update guidance. <p>Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Access Remote Code Execution vulnerability
Microsoft Office Access Remote Code Execution vulnerability (CVE-2026-69778) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.