Skip to main content
All vendors

Microsoft security briefs

268 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-49159

Microsoft Graph Information Disclosure vulnerability

Microsoft Graph Information Disclosure vulnerability (CVE-2026-49159) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-50517

Microsoft M365 Copilot Remote Code Execution vulnerability

Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-50517) was added to Microsoft’s security update guidance. Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-54120

Microsoft Surface Remote Code Execution vulnerability

Microsoft Surface Remote Code Execution vulnerability (CVE-2026-54120) was added to Microsoft’s security update guidance. Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56160

Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability

Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability (CVE-2026-56160) was added to Microsoft’s security update guidance. Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56163

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-56163) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56165

Microsoft Account Remote Code Execution vulnerability

Microsoft Account Remote Code Execution vulnerability (CVE-2026-56165) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56167

Azure AI Search Elevation of Privilege vulnerability

Azure AI Search Elevation of Privilege vulnerability (CVE-2026-56167) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56191

Microsoft Exchange Online Tampering vulnerability

Microsoft Exchange Online Tampering vulnerability (CVE-2026-56191) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58275

Azure DNS Elevation of Privilege vulnerability

Azure DNS Elevation of Privilege vulnerability (CVE-2026-58275) was added to Microsoft’s security update guidance. Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58630

Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability

Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability (CVE-2026-58630) was added to Microsoft’s security update guidance. Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-62825

Azure Key Vault Elevation of Privilege vulnerability

Azure Key Vault Elevation of Privilege vulnerability (CVE-2026-62825) was added to Microsoft’s security update guidance. Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-55008

Microsoft Exchange Server Spoofing vulnerability

Microsoft Exchange Server Spoofing vulnerability (CVE-2026-55008) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-55121

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55121) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-56181

Windows Network Address Translation (NAT) Spoofing vulnerability

Windows Network Address Translation (NAT) Spoofing vulnerability (CVE-2026-56181) was added to Microsoft’s security update guidance. Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58529

Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability

Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability (CVE-2026-58529) was added to Microsoft’s security update guidance. Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58531

Windows SMB Elevation of Privilege vulnerability

Windows SMB Elevation of Privilege vulnerability (CVE-2026-58531) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58532

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-58532) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58533

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58533) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58534

Windows Input Method Editor (IME) Elevation of Privilege vulnerability

Windows Input Method Editor (IME) Elevation of Privilege vulnerability (CVE-2026-58534) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58535

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58535) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58536

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-58536) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58537

Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege vulnerability

Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege vulnerability (CVE-2026-58537) was added to Microsoft’s security update guidance. Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58539

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58539) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-58540

Windows Installer Elevation of Privilege vulnerability

Windows Installer Elevation of Privilege vulnerability (CVE-2026-58540) was added to Microsoft’s security update guidance. Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.