Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-61349

Windows Work Folder Service Elevation of Privilege vulnerability

Windows Work Folder Service Elevation of Privilege vulnerability (CVE-2026-61349) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54124

Windows Terminal Remote Code Execution vulnerability

Windows Terminal Remote Code Execution vulnerability (CVE-2026-54124) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54112

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-54112) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50679

Windows Search Service Elevation of Privilege vulnerability

Windows Search Service Elevation of Privilege vulnerability (CVE-2026-50679) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50676

Windows Media Elevation of Privilege vulnerability

Windows Media Elevation of Privilege vulnerability (CVE-2026-50676) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2025-2137

Out of bounds read in V8 in Microsoft Edge vulnerability

Out of bounds read in V8 in Microsoft Edge vulnerability (CVE-2025-2137) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2025-1920

Type Confusion in V8 in Microsoft Edge vulnerability

Type Confusion in V8 in Microsoft Edge vulnerability (CVE-2025-1920) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69492

Windows Partition Management Driver Elevation of Privilege vulnerability

Windows Partition Management Driver Elevation of Privilege vulnerability (CVE-2026-69492) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62693

Windows MIDI Service Module Elevation of Privileges vulnerability

Windows MIDI Service Module Elevation of Privileges vulnerability (CVE-2026-62693) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-45499

Azure OpenAI Elevation of Privilege vulnerability

Azure OpenAI Elevation of Privilege vulnerability (CVE-2026-45499) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-85880

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-85880). Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. CISA remediation due date: 2026-09-22. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85877

Windows Print Spooler Remote Code Execution vulnerability

Windows Print Spooler Remote Code Execution vulnerability (CVE-2026-85877) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-85875

Microsoft Office Excel Information Disclosure vulnerability

Microsoft Office Excel Information Disclosure vulnerability (CVE-2026-85875) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-85360

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-85360) was added to Microsoft’s security update guidance. <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84359

Information leak in Skia in Microsoft Edge vulnerability

Information leak in Skia in Microsoft Edge vulnerability (CVE-2026-84359) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84358

Improper privilege management in Downloads in Microsoft Edge vulnerability

Improper privilege management in Downloads in Microsoft Edge vulnerability (CVE-2026-84358) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84357

Improper input validation in Omnibox in Microsoft Edge vulnerability

Improper input validation in Omnibox in Microsoft Edge vulnerability (CVE-2026-84357) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84356

UI misrepresentation in FullScreen in Microsoft Edge vulnerability

UI misrepresentation in FullScreen in Microsoft Edge vulnerability (CVE-2026-84356) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84355

Incorrect authorization in Navigation in Microsoft Edge vulnerability

Incorrect authorization in Navigation in Microsoft Edge vulnerability (CVE-2026-84355) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84354

Incorrect authorization in FileSystem in Microsoft Edge vulnerability

Incorrect authorization in FileSystem in Microsoft Edge vulnerability (CVE-2026-84354) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84353

Use after free in Shared Tab Groups in Microsoft Edge vulnerability

Use after free in Shared Tab Groups in Microsoft Edge vulnerability (CVE-2026-84353) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84351

Buffer overflow in GPU in Microsoft Edge vulnerability

Buffer overflow in GPU in Microsoft Edge vulnerability (CVE-2026-84351) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84350

Use after free in TabStrip in Microsoft Edge vulnerability

Use after free in TabStrip in Microsoft Edge vulnerability (CVE-2026-84350) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84349

Use after free in Browser in Microsoft Edge vulnerability

Use after free in Browser in Microsoft Edge vulnerability (CVE-2026-84349) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.