Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-69818

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69818) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69817

Windows Bluetooth Port Driver Elevation of Privilege vulnerability

Windows Bluetooth Port Driver Elevation of Privilege vulnerability (CVE-2026-69817) was added to Microsoft’s security update guidance. Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69816

Windows Accounts Control Elevation of Privilege vulnerability

Windows Accounts Control Elevation of Privilege vulnerability (CVE-2026-69816) was added to Microsoft’s security update guidance. <p>Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69814

Windows Credential Providers Elevation of Privilege vulnerability

Windows Credential Providers Elevation of Privilege vulnerability (CVE-2026-69814) was added to Microsoft’s security update guidance. Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69813

Windows DNS Server Remote Code Execution vulnerability

Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69813) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69809

Windows Active Directory Domain Services Denial of Service vulnerability

Windows Active Directory Domain Services Denial of Service vulnerability (CVE-2026-69809) was added to Microsoft’s security update guidance. Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69804

Microsoft Office SharePoint Remote Code Execution vulnerability

Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69804) was added to Microsoft’s security update guidance. <p>Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69803

Windows DHCP Server Information Disclosure vulnerability

Windows DHCP Server Information Disclosure vulnerability (CVE-2026-69803) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69801

Windows Audio Service Elevation of Privilege vulnerability

Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-69801) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69799

Windows Hello Elevation of Privilege vulnerability

Windows Hello Elevation of Privilege vulnerability (CVE-2026-69799) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69797

Microsoft Office PowerPoint Remote Code Execution vulnerability

Microsoft Office PowerPoint Remote Code Execution vulnerability (CVE-2026-69797) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69794

Windows Encrypting File System (EFS) Information Disclosure vulnerability

Windows Encrypting File System (EFS) Information Disclosure vulnerability (CVE-2026-69794) was added to Microsoft’s security update guidance. Buffer over-read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69793

Windows TCP/IP Security Feature Bypass vulnerability

Windows TCP/IP Security Feature Bypass vulnerability (CVE-2026-69793) was added to Microsoft’s security update guidance. Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69792

Windows Win32K Security Feature Bypass vulnerability

Windows Win32K Security Feature Bypass vulnerability (CVE-2026-69792) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69791

Windows Device Association Service Elevation of Privilege vulnerability

Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69791) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69790

Windows Credential Providers Elevation of Privilege vulnerability

Windows Credential Providers Elevation of Privilege vulnerability (CVE-2026-69790) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69787

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69787) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69786

Windows Text Shaping Remote Code Execution vulnerability

Windows Text Shaping Remote Code Execution vulnerability (CVE-2026-69786) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Text Shaping allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69785

Windows Smart Card Elevation of Privilege vulnerability

Windows Smart Card Elevation of Privilege vulnerability (CVE-2026-69785) was added to Microsoft’s security update guidance. Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69784

Windows Hello Elevation of Privilege vulnerability

Windows Hello Elevation of Privilege vulnerability (CVE-2026-69784) was added to Microsoft’s security update guidance. <p>Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69782

Windows DNS Server Remote Code Execution vulnerability

Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69782) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69781

Windows DHCP Client Denial of Service vulnerability

Windows DHCP Client Denial of Service vulnerability (CVE-2026-69781) was added to Microsoft’s security update guidance. <p>Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69779

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69779) was added to Microsoft’s security update guidance. <p>Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69778

Microsoft Office Access Remote Code Execution vulnerability

Microsoft Office Access Remote Code Execution vulnerability (CVE-2026-69778) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.