Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-69607

Windows Deployment Services Remote Code Execution vulnerability

Windows Deployment Services Remote Code Execution vulnerability (CVE-2026-69607) was added to Microsoft’s security update guidance. <p>Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69606

Windows Shell Elevation of Privilege vulnerability

Windows Shell Elevation of Privilege vulnerability (CVE-2026-69606) was added to Microsoft’s security update guidance. <p>Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69605

Microsoft Install Service Elevation of Privilege vulnerability

Microsoft Install Service Elevation of Privilege vulnerability (CVE-2026-69605) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69604

Windows Audio Service Elevation of Privilege vulnerability

Windows Audio Service Elevation of Privilege vulnerability (CVE-2026-69604) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69603

Windows Hyper-V Remote Code Execution vulnerability

Windows Hyper-V Remote Code Execution vulnerability (CVE-2026-69603) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69602

Windows PrintWorkflowUserSvc Elevation of Privilege vulnerability

Windows PrintWorkflowUserSvc Elevation of Privilege vulnerability (CVE-2026-69602) was added to Microsoft’s security update guidance. <p>Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69601

Microsoft Windows Media Foundation Remote Code Execution vulnerability

Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-69601) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69600

Microsoft Windows Search Component Elevation of Privilege vulnerability

Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69600) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69598

Windows iSCSI Remote Code Execution vulnerability

Windows iSCSI Remote Code Execution vulnerability (CVE-2026-69598) was added to Microsoft’s security update guidance. <p>Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69597

Windows HTTP.sys Elevation of Privilege vulnerability

Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-69597) was added to Microsoft’s security update guidance. <p>Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69595

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution vulnerability (CVE-2026-69595) was added to Microsoft’s security update guidance. <p>Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69594

Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability

Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability (CVE-2026-69594) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69593

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69593) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69592

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege vulnerability (CVE-2026-69592) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69591

Windows NTFS Information Disclosure vulnerability

Windows NTFS Information Disclosure vulnerability (CVE-2026-69591) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69590

Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability

Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability (CVE-2026-69590) was added to Microsoft’s security update guidance. Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69589

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69589) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69588

Windows TCP/IP Denial of Service vulnerability

Windows TCP/IP Denial of Service vulnerability (CVE-2026-69588) was added to Microsoft’s security update guidance. Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69587

Windows Internet Key Exchange (IKE) Extension Denial of Service vulnerability

Windows Internet Key Exchange (IKE) Extension Denial of Service vulnerability (CVE-2026-69587) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69586

Microsoft Windows PDF Remote Code Execution vulnerability

Microsoft Windows PDF Remote Code Execution vulnerability (CVE-2026-69586) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69585

Microsoft Windows Search Component Elevation of Privilege vulnerability

Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-69585) was added to Microsoft’s security update guidance. <p>Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69584

Windows USB Video Driver Elevation of Privilege vulnerability

Windows USB Video Driver Elevation of Privilege vulnerability (CVE-2026-69584) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69583

Windows Biometric Service Elevation of Privilege vulnerability

Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69583) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69582

Windows Volume Manager Extension Driver Elevation of Privilege vulnerability

Windows Volume Manager Extension Driver Elevation of Privilege vulnerability (CVE-2026-69582) was added to Microsoft’s security update guidance. <p>Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.