Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-68830

Windows Universal Plug and Play (UPnP) Device Host Information Disclosure vulnerability

Windows Universal Plug and Play (UPnP) Device Host Information Disclosure vulnerability (CVE-2026-68830) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68827

Windows GDI+ Elevation of Privilege vulnerability

Windows GDI+ Elevation of Privilege vulnerability (CVE-2026-68827) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68825

Windows Bind Filter Driver Elevation of Privilege vulnerability

Windows Bind Filter Driver Elevation of Privilege vulnerability (CVE-2026-68825) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68787

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68787) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68786

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68786) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68785

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68785) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68784

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68784) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68781

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68781) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68780

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68780) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68779

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68779) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68778

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68778) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68777

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68777) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68776

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-68776) was added to Microsoft’s security update guidance. Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68775

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-68775) was added to Microsoft’s security update guidance. Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67648

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67648) was added to Microsoft’s security update guidance. <p>Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67645

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67645) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67643

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67643) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67642

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67642) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67641

Microsoft SQL Server Denial of Service vulnerability

Microsoft SQL Server Denial of Service vulnerability (CVE-2026-67641) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67639

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67639) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67638

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67638) was added to Microsoft’s security update guidance. Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67636

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67636) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67633

Microsoft SQL Server Denial of Service vulnerability

Microsoft SQL Server Denial of Service vulnerability (CVE-2026-67633) was added to Microsoft’s security update guidance. Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67631

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67631) was added to Microsoft’s security update guidance. Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.