Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows DHCP Client Elevation of Privilege vulnerability
Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-69777) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Elevation of Privilege vulnerability
Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-69775) was added to Microsoft’s security update guidance. <p>Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69773) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows Network File System Remote Code Execution vulnerability
Windows Network File System Remote Code Execution vulnerability (CVE-2026-69772) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Network File System allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Container Manager Service Security Feature Bypass vulnerability
Windows Container Manager Service Security Feature Bypass vulnerability (CVE-2026-69771) was added to Microsoft’s security update guidance. <p>Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Information Disclosure vulnerability
Windows Spaceport.sys Information Disclosure vulnerability (CVE-2026-69770) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows HTTP Print Provider Remote Code Execution vulnerability
Windows HTTP Print Provider Remote Code Execution vulnerability (CVE-2026-69769) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows RNDIS Remote Code Execution vulnerability
Windows RNDIS Remote Code Execution vulnerability (CVE-2026-69768) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office PowerPoint Remote Code Execution vulnerability
Microsoft Office PowerPoint Remote Code Execution vulnerability (CVE-2026-69767) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-69764) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69762) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-69761) was added to Microsoft’s security update guidance. <p>Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Denial of Service vulnerability
Windows Kerberos Denial of Service vulnerability (CVE-2026-69760) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-69759) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability (CVE-2026-69758) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-69757) was added to Microsoft’s security update guidance. <p>Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Denial of Service vulnerability
Windows Kerberos Denial of Service vulnerability (CVE-2026-69744) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Publisher Remote Code Execution vulnerability
Microsoft Office Publisher Remote Code Execution vulnerability (CVE-2026-69742) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Information Disclosure vulnerability
Windows Spaceport.sys Information Disclosure vulnerability (CVE-2026-69741) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Hello Elevation of Privilege vulnerability
Windows Hello Elevation of Privilege vulnerability (CVE-2026-69740) was added to Microsoft’s security update guidance. <p>Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-69739) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69738) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Broadcast DVR User Service Elevation of Privilege vulnerability
Windows Broadcast DVR User Service Elevation of Privilege vulnerability (CVE-2026-69735) was added to Microsoft’s security update guidance. Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Information Disclosure vulnerability
Microsoft Office Word Information Disclosure vulnerability (CVE-2026-69734) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.