Microsoft security briefs
3323 published alerts for Microsoft products and services.
Information leak in MediaCapture in Microsoft Edge vulnerability
Information leak in MediaCapture in Microsoft Edge vulnerability (CVE-2026-84348) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in WebRTC in Microsoft Edge vulnerability
Use after free in WebRTC in Microsoft Edge vulnerability (CVE-2026-84347) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Incorrect authorization in TabStrip in Microsoft Edge vulnerability
Incorrect authorization in TabStrip in Microsoft Edge vulnerability (CVE-2026-84335) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Incorrect authorization in Chromoting in Microsoft Edge vulnerability
Incorrect authorization in Chromoting in Microsoft Edge vulnerability (CVE-2026-84334) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Incorrect authorization in SiteSettings in Microsoft Edge vulnerability
Incorrect authorization in SiteSettings in Microsoft Edge vulnerability (CVE-2026-84332) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Incorrect authorization in Actor in Microsoft Edge vulnerability
Incorrect authorization in Actor in Microsoft Edge vulnerability (CVE-2026-84331) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Confused deputy in CredentialProvider in Microsoft Edge vulnerability
Confused deputy in CredentialProvider in Microsoft Edge vulnerability (CVE-2026-84329) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Missing authorization in FileSystem in Microsoft Edge vulnerability
Missing authorization in FileSystem in Microsoft Edge vulnerability (CVE-2026-84328) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Incorrect authorization in Autofill in Microsoft Edge vulnerability
Incorrect authorization in Autofill in Microsoft Edge vulnerability (CVE-2026-84327) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Uninitialized resource in V8 in Microsoft Edge vulnerability
Uninitialized resource in V8 in Microsoft Edge vulnerability (CVE-2026-84326) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Improper input validation in DataTransfer in Microsoft Edge vulnerability
Improper input validation in DataTransfer in Microsoft Edge vulnerability (CVE-2026-84325) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Proxy in Microsoft Edge vulnerability
Use after free in Proxy in Microsoft Edge vulnerability (CVE-2026-84324) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Missing authorization in FileSystem in Microsoft Edge vulnerability
Missing authorization in FileSystem in Microsoft Edge vulnerability (CVE-2026-84323) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Microsoft Authentication Library (MSAL) for Node.js Spoofing vulnerability
Microsoft Authentication Library (MSAL) for Node.js Spoofing vulnerability (CVE-2026-84003) was added to Microsoft’s security update guidance. <p>Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Key Distribution Center Denial of Service vulnerability
Windows Key Distribution Center Denial of Service vulnerability (CVE-2026-84001) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Graphics Component Remote Code Execution vulnerability
Microsoft Graphics Component Remote Code Execution vulnerability (CVE-2026-84000) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege vulnerability
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege vulnerability (CVE-2026-83999) was added to Microsoft’s security update guidance. <p>Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Message Queuing Remote Code Execution vulnerability
Windows Message Queuing Remote Code Execution vulnerability (CVE-2026-83997) was added to Microsoft’s security update guidance. <p>Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Error Reporting Elevation of Privilege vulnerability
Windows Error Reporting Elevation of Privilege vulnerability (CVE-2026-83996) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-83995) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Imaging Component Remote Code Execution vulnerability
Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-83992) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Tampering vulnerability
Windows Cloud Files Mini Filter Driver Tampering vulnerability (CVE-2026-83991) was added to Microsoft’s security update guidance. <p>Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Graphics Component Elevation of Privilege vulnerability
Microsoft Graphics Component Elevation of Privilege vulnerability (CVE-2026-83990) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Services for NFS ONCRPC XDR Driver Denial of Service vulnerability
Windows Services for NFS ONCRPC XDR Driver Denial of Service vulnerability (CVE-2026-83989) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.