Microsoft security briefs
3323 published alerts for Microsoft products and services.
Skype for Business Spoofing vulnerability
Skype for Business Spoofing vulnerability (CVE-2026-69642) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Elevation of Privilege vulnerability
Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-69641) was added to Microsoft’s security update guidance. <p>Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-69638) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-69637) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Information Disclosure vulnerability
Microsoft Office SharePoint Information Disclosure vulnerability (CVE-2026-69636) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-69632) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows DNS Denial of Service vulnerability
Windows DNS Denial of Service vulnerability (CVE-2026-69631) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69630) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Outlook Remote Code Execution vulnerability
Microsoft Office Outlook Remote Code Execution vulnerability (CVE-2026-69629) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Remote Code Execution vulnerability
Windows iSCSI Remote Code Execution vulnerability (CVE-2026-69628) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Licensing Service Information Disclosure vulnerability
Windows Remote Desktop Licensing Service Information Disclosure vulnerability (CVE-2026-69627) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-69626) was added to Microsoft’s security update guidance. Microsoft is announcing the availability of the security updates for Microsoft Office for Mac. Customers running affected Mac software should install the update for their product to be protected from this vulnerability. Customers running other Microsoft Office software do not… If you need help checking exposure, call (864) 335-9223.
Windows HTTP Print Provider Remote Code Execution vulnerability
Windows HTTP Print Provider Remote Code Execution vulnerability (CVE-2026-69623) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-69620) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows exFAT File System Elevation of Privilege vulnerability
Windows exFAT File System Elevation of Privilege vulnerability (CVE-2026-69619) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows SMB Client Information Disclosure vulnerability
Windows SMB Client Information Disclosure vulnerability (CVE-2026-69618) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-69617) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Information Disclosure vulnerability
Windows Remote Desktop Services Information Disclosure vulnerability (CVE-2026-69616) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Spoofing vulnerability
Microsoft Office SharePoint Spoofing vulnerability (CVE-2026-69615) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Access Remote Code Execution vulnerability
Microsoft Office Access Remote Code Execution vulnerability (CVE-2026-69614) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Image Acquisition Elevation of Privilege vulnerability
Windows Image Acquisition Elevation of Privilege vulnerability (CVE-2026-69613) was added to Microsoft’s security update guidance. <p>Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Error Reporting Elevation of Privilege vulnerability
Windows Error Reporting Elevation of Privilege vulnerability (CVE-2026-69612) was added to Microsoft’s security update guidance. <p>Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69610) was added to Microsoft’s security update guidance. <p>Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Elevation of Privilege vulnerability
Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69608) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.