Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-69730) was added to Microsoft’s security update guidance. <p>Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Credential Providers Remote Code Execution vulnerability
Windows Credential Providers Remote Code Execution vulnerability (CVE-2026-69729) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69727) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hello Elevation of Privilege vulnerability
Windows Hello Elevation of Privilege vulnerability (CVE-2026-69725) was added to Microsoft’s security update guidance. <p>Double free in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Remote Code Execution vulnerability
Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69724) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Information Disclosure vulnerability
Windows Kernel Information Disclosure vulnerability (CVE-2026-69723) was added to Microsoft’s security update guidance. <p>Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-69722) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows MIDI Service Module Elevation of Privileges vulnerability
Windows MIDI Service Module Elevation of Privileges vulnerability (CVE-2026-69720) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Information Disclosure vulnerability
Microsoft Office Word Information Disclosure vulnerability (CVE-2026-69719) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Group Policy Elevation of Privilege vulnerability
Windows Group Policy Elevation of Privilege vulnerability (CVE-2026-69717) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Elevation of Privilege vulnerability
Microsoft Office SharePoint Elevation of Privilege vulnerability (CVE-2026-69716) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Direct Show Remote Code Execution vulnerability
Windows Direct Show Remote Code Execution vulnerability (CVE-2026-69715) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69714) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Secure Boot Security Feature Bypass vulnerability
Windows Secure Boot Security Feature Bypass vulnerability (CVE-2026-69713) was added to Microsoft’s security update guidance. <p>Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Key Distribution Center Remote Code Execution vulnerability
Windows Key Distribution Center Remote Code Execution vulnerability (CVE-2026-69712) was added to Microsoft’s security update guidance. <p>Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Service Elevation of Privilege vulnerability
Windows Device Association Service Elevation of Privilege vulnerability (CVE-2026-69711) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Hello Elevation of Privilege vulnerability
Windows Hello Elevation of Privilege vulnerability (CVE-2026-69710) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-69709) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Web Platform Storage Elevation of Privilege vulnerability
Windows Web Platform Storage Elevation of Privilege vulnerability (CVE-2026-69708) was added to Microsoft’s security update guidance. <p>Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69707) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69706) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows IP Address Management (IPAM) Service Elevation of Privilege vulnerability
Windows IP Address Management (IPAM) Service Elevation of Privilege vulnerability (CVE-2026-69694) was added to Microsoft’s security update guidance. <p>Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Device Association Broker Service Elevation of Privilege vulnerability
Windows Device Association Broker Service Elevation of Privilege vulnerability (CVE-2026-69693) was added to Microsoft’s security update guidance. <p>Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Audio Service Elevation of Privilege vulnerability
Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-69692) was added to Microsoft’s security update guidance. Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.