Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows NDIS Elevation of Privilege vulnerability
Windows NDIS Elevation of Privilege vulnerability (CVE-2026-69357) was added to Microsoft’s security update guidance. Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Spoofing vulnerability
Microsoft Exchange Server Spoofing vulnerability (CVE-2026-69356) was added to Microsoft’s security update guidance. <p>Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution vulnerability
Microsoft Exchange Server Remote Code Execution vulnerability (CVE-2026-69355) was added to Microsoft’s security update guidance. <p>External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Text Shaping Information Disclosure vulnerability
Windows Text Shaping Information Disclosure vulnerability (CVE-2026-69353) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Biometric Service Elevation of Privilege vulnerability
Windows Biometric Service Elevation of Privilege vulnerability (CVE-2026-69352) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Universal Plug and Play (UPnP) Device Host Information Disclosure vulnerability
Windows Universal Plug and Play (UPnP) Device Host Information Disclosure vulnerability (CVE-2026-69351) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Elevation of Privilege vulnerability
Windows Overlay Filter Elevation of Privilege vulnerability (CVE-2026-69350) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Management Instrumentation Information Disclosure vulnerability
Windows Management Instrumentation Information Disclosure vulnerability (CVE-2026-69349) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69348) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Fast FAT Driver Remote Code Execution vulnerability
Windows Fast FAT Driver Remote Code Execution vulnerability (CVE-2026-69347) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Elevation of Privilege vulnerability
Windows Print Spooler Components Elevation of Privilege vulnerability (CVE-2026-69346) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Information Disclosure vulnerability
Microsoft Standard XPS Information Disclosure vulnerability (CVE-2026-69345) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Components Information Disclosure vulnerability
Windows Print Spooler Components Information Disclosure vulnerability (CVE-2026-69344) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Information Disclosure vulnerability
Windows Overlay Filter Information Disclosure vulnerability (CVE-2026-69343) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-69342) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Image Acquisition Elevation of Privilege vulnerability
Windows Image Acquisition Elevation of Privilege vulnerability (CVE-2026-69341) was added to Microsoft’s security update guidance. <p>Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69340) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows MIDI Service Module Information Disclosure vulnerability
Windows MIDI Service Module Information Disclosure vulnerability (CVE-2026-69339) was added to Microsoft’s security update guidance. <p>Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Registry Elevation of Privilege vulnerability
Windows Registry Elevation of Privilege vulnerability (CVE-2026-69337) was added to Microsoft’s security update guidance. <p>Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Standard XPS Elevation of Privilege vulnerability
Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-69336) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69335) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Volume Manager Extension Driver Remote Code Execution vulnerability
Windows Volume Manager Extension Driver Remote Code Execution vulnerability (CVE-2026-69334) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-69333) was added to Microsoft’s security update guidance. <p>Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69332) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.