Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Universal Plug and Play (UPnP) Device Host Information Disclosure vulnerability
Windows Universal Plug and Play (UPnP) Device Host Information Disclosure vulnerability (CVE-2026-68830) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows GDI+ Elevation of Privilege vulnerability
Windows GDI+ Elevation of Privilege vulnerability (CVE-2026-68827) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Bind Filter Driver Elevation of Privilege vulnerability
Windows Bind Filter Driver Elevation of Privilege vulnerability (CVE-2026-68825) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68787) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68786) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68785) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68784) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68781) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68780) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68779) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68778) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68777) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68776) was added to Microsoft’s security update guidance. Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68775) was added to Microsoft’s security update guidance. Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67648) was added to Microsoft’s security update guidance. <p>Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Information Disclosure vulnerability
Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67645) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67643) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67642) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Denial of Service vulnerability
Microsoft SQL Server Denial of Service vulnerability (CVE-2026-67641) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67639) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67638) was added to Microsoft’s security update guidance. Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67636) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Denial of Service vulnerability
Microsoft SQL Server Denial of Service vulnerability (CVE-2026-67633) was added to Microsoft’s security update guidance. Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67631) was added to Microsoft’s security update guidance. Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.