Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Spaceport.sys Elevation of Privilege vulnerability
Windows Spaceport.sys Elevation of Privilege vulnerability (CVE-2026-69691) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Spoofing vulnerability
Microsoft Office SharePoint Spoofing vulnerability (CVE-2026-69690) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69689) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Encrypting File System (EFS) Elevation of Privilege vulnerability
Windows Encrypting File System (EFS) Elevation of Privilege vulnerability (CVE-2026-69688) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability
Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69687) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-69686) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Elevation of Privilege vulnerability
Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-69685) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Error Reporting Information Disclosure vulnerability
Windows Error Reporting Information Disclosure vulnerability (CVE-2026-69684) was added to Microsoft’s security update guidance. Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Information Disclosure vulnerability
Microsoft Office SharePoint Information Disclosure vulnerability (CVE-2026-69683) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Host Guardian Service Elevation of Privilege vulnerability
Windows Host Guardian Service Elevation of Privilege vulnerability (CVE-2026-69682) was added to Microsoft’s security update guidance. <p>Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows DNS Spoofing vulnerability
Windows DNS Spoofing vulnerability (CVE-2026-69680) was added to Microsoft’s security update guidance. Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-69679) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office PowerPoint Remote Code Execution vulnerability
Microsoft Office PowerPoint Remote Code Execution vulnerability (CVE-2026-69678) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Remote Code Execution vulnerability
Windows Kerberos Remote Code Execution vulnerability (CVE-2026-69676) was added to Microsoft’s security update guidance. <p>Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Modern Device Management (MDM) Security Feature Bypass vulnerability
Windows Modern Device Management (MDM) Security Feature Bypass vulnerability (CVE-2026-69674) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Information Disclosure vulnerability
Windows DNS Information Disclosure vulnerability (CVE-2026-69672) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-69671) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows Kernel Remote Code Execution vulnerability
Windows Kernel Remote Code Execution vulnerability (CVE-2026-69669) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Accounts Control Elevation of Privilege vulnerability
Windows Accounts Control Elevation of Privilege vulnerability (CVE-2026-69654) was added to Microsoft’s security update guidance. <p>Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69652) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Notification Elevation of Privilege vulnerability
Windows Notification Elevation of Privilege vulnerability (CVE-2026-69648) was added to Microsoft’s security update guidance. Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Skype for Business Spoofing vulnerability
Skype for Business Spoofing vulnerability (CVE-2026-69646) was added to Microsoft’s security update guidance. <p>Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Message Queuing Elevation of Privilege vulnerability
Windows Message Queuing Elevation of Privilege vulnerability (CVE-2026-69645) was added to Microsoft’s security update guidance. <p>Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Elevation of Privilege vulnerability
Windows Spaceport.sys Elevation of Privilege vulnerability (CVE-2026-69643) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.