Microsoft security briefs
3323 published alerts for Microsoft products and services.
Microsoft Windows Media Foundation Remote Code Execution vulnerability
Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-69386) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Elevation of Privilege vulnerability
Windows TCP/IP Elevation of Privilege vulnerability (CVE-2026-69385) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Shell Elevation of Privilege vulnerability
Windows Shell Elevation of Privilege vulnerability (CVE-2026-69383) was added to Microsoft’s security update guidance. <p>External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Information Disclosure vulnerability
Microsoft Exchange Server Information Disclosure vulnerability (CVE-2026-69382) was added to Microsoft’s security update guidance. <p>Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Storage Port Driver Information Disclosure vulnerability
Windows Storage Port Driver Information Disclosure vulnerability (CVE-2026-69381) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Elevation of Privilege vulnerability
Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-69380) was added to Microsoft’s security update guidance. <p>Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69379) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Denial of Service vulnerability
Microsoft Exchange Server Denial of Service vulnerability (CVE-2026-69378) was added to Microsoft’s security update guidance. <p>Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Modern Device Management (MDM) Elevation of Privilege vulnerability
Windows Modern Device Management (MDM) Elevation of Privilege vulnerability (CVE-2026-69377) was added to Microsoft’s security update guidance. <p>Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Information Disclosure vulnerability
Microsoft Standard XPS Information Disclosure vulnerability (CVE-2026-69376) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Tampering vulnerability
Microsoft Exchange Server Tampering vulnerability (CVE-2026-69375) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows SMB Server Denial of Service vulnerability
Windows SMB Server Denial of Service vulnerability (CVE-2026-69374) was added to Microsoft’s security update guidance. <p>Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Elevation of Privilege vulnerability
Windows Overlay Filter Elevation of Privilege vulnerability (CVE-2026-69373) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Network File System Denial of Service vulnerability
Windows Network File System Denial of Service vulnerability (CVE-2026-69372) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Elevation of Privilege vulnerability
Windows Overlay Filter Elevation of Privilege vulnerability (CVE-2026-69371) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows DNS Information Disclosure vulnerability
Windows DNS Information Disclosure vulnerability (CVE-2026-69369) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Elevation of Privilege vulnerability
Windows Overlay Filter Elevation of Privilege vulnerability (CVE-2026-69368) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Information Disclosure vulnerability
Microsoft Standard XPS Information Disclosure vulnerability (CVE-2026-69367) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-69366) was added to Microsoft’s security update guidance. <p>Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability
Microsoft Local Security Authority (LSA) Server Elevation of Privilege vulnerability (CVE-2026-69365) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Elevation of Privilege vulnerability
Windows Print Spooler Components Elevation of Privilege vulnerability (CVE-2026-69364) was added to Microsoft’s security update guidance. <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Error Reporting Elevation of Privilege vulnerability
Windows Error Reporting Elevation of Privilege vulnerability (CVE-2026-69362) was added to Microsoft’s security update guidance. Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Spoofing vulnerability
Microsoft Exchange Server Spoofing vulnerability (CVE-2026-69361) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-69360) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.