Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-69271

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-69271) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69270

Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability

Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege vulnerability (CVE-2026-69270) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69269

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-69269) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69268

Microsoft Office SharePoint Remote Code Execution vulnerability

Microsoft Office SharePoint Remote Code Execution vulnerability (CVE-2026-69268) was added to Microsoft’s security update guidance. <p>Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69267

Windows Connected User Experiences and Telemetry Information Disclosure vulnerability

Windows Connected User Experiences and Telemetry Information Disclosure vulnerability (CVE-2026-69267) was added to Microsoft’s security update guidance. Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69266

Windows DHCP Server Remote Code Execution vulnerability

Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-69266) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69265

Windows NTFS Elevation of Privilege vulnerability

Windows NTFS Elevation of Privilege vulnerability (CVE-2026-69265) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68898

Windows iSCSI Denial of Service vulnerability

Windows iSCSI Denial of Service vulnerability (CVE-2026-68898) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68897

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-68897) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68896

Microsoft Windows Search Component Elevation of Privilege vulnerability

Microsoft Windows Search Component Elevation of Privilege vulnerability (CVE-2026-68896) was added to Microsoft’s security update guidance. <p>Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68894

Windows Error Reporting Elevation of Privilege vulnerability

Windows Error Reporting Elevation of Privilege vulnerability (CVE-2026-68894) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68892

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-68892) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68891

Microsoft Standard XPS Information Disclosure vulnerability

Microsoft Standard XPS Information Disclosure vulnerability (CVE-2026-68891) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68890

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-68890) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68889

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-68889) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68888

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-68888) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68887

Windows Message Queuing Queue Manager Denial of Service vulnerability

Windows Message Queuing Queue Manager Denial of Service vulnerability (CVE-2026-68887) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68886

Windows Network Connection Broker Information Disclosure vulnerability

Windows Network Connection Broker Information Disclosure vulnerability (CVE-2026-68886) was added to Microsoft’s security update guidance. Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68885

Microsoft Standard XPS Elevation of Privilege vulnerability

Microsoft Standard XPS Elevation of Privilege vulnerability (CVE-2026-68885) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68884

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-68884) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68881

Microsoft Standard XPS Information Disclosure vulnerability

Microsoft Standard XPS Information Disclosure vulnerability (CVE-2026-68881) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68880

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-68880) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68878

Windows Fast FAT Driver Elevation of Privilege vulnerability

Windows Fast FAT Driver Elevation of Privilege vulnerability (CVE-2026-68878) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68877

Windows Storage Spaces Controller Remote Code Execution vulnerability

Windows Storage Spaces Controller Remote Code Execution vulnerability (CVE-2026-68877) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.