Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-66814

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-66814) was added to Microsoft’s security update guidance. <p>Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66308

Skype for Business and Lync Denial of Service vulnerability

Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66308) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-66307

Skype for Business and Lync Denial of Service vulnerability

Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66307) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66306

Skype for Business Information Disclosure vulnerability

Skype for Business Information Disclosure vulnerability (CVE-2026-66306) was added to Microsoft’s security update guidance. <p>Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66305

Skype for Business Spoofing vulnerability

Skype for Business Spoofing vulnerability (CVE-2026-66305) was added to Microsoft’s security update guidance. Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66304

Skype for Business Information Disclosure vulnerability

Skype for Business Information Disclosure vulnerability (CVE-2026-66304) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-66303

Skype for Business and Lync Denial of Service vulnerability

Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66303) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66302

Skype for Business Remote Code Execution vulnerability

Skype for Business Remote Code Execution vulnerability (CVE-2026-66302) was added to Microsoft’s security update guidance. <p>External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65812

Microsoft Teams for Android Information Disclosure vulnerability

Microsoft Teams for Android Information Disclosure vulnerability (CVE-2026-65812) was added to Microsoft’s security update guidance. Corrected fix build number. Informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65789

Windows DNS Server Remote Code Execution vulnerability

Windows DNS Server Remote Code Execution vulnerability (CVE-2026-65789) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65772

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-65772) was added to Microsoft’s security update guidance. <p>Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65669

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-65669) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64918

Microsoft Office Spoofing vulnerability

Microsoft Office Spoofing vulnerability (CVE-2026-64918) was added to Microsoft’s security update guidance. Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63523

Skype for Business Spoofing vulnerability

Skype for Business Spoofing vulnerability (CVE-2026-63523) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62916

Microsoft Entra ID Elevation of Privilege vulnerability

Microsoft Entra ID Elevation of Privilege vulnerability (CVE-2026-62916) was added to Microsoft’s security update guidance. <p>Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62906

Microsoft Discovery Studio Information Disclosure vulnerability

Microsoft Discovery Studio Information Disclosure vulnerability (CVE-2026-62906) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62895

Azure Arc SQL Server Extension Elevation of Privilege vulnerability

Azure Arc SQL Server Extension Elevation of Privilege vulnerability (CVE-2026-62895) was added to Microsoft’s security update guidance. <p>Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62893

Windows Deployment Services TFTP Server Remote Code Execution vulnerability

Windows Deployment Services TFTP Server Remote Code Execution vulnerability (CVE-2026-62893) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62878

Windows DNS Server Remote Code Execution vulnerability

Windows DNS Server Remote Code Execution vulnerability (CVE-2026-62878) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62823

Windows DHCP Server Remote Code Execution vulnerability

Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-62823) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62820

Windows DNS Server Remote Code Execution vulnerability

Windows DNS Server Remote Code Execution vulnerability (CVE-2026-62820) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62817

Windows DNS Server Remote Code Execution vulnerability

Windows DNS Server Remote Code Execution vulnerability (CVE-2026-62817) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62814

Windows DHCP Server Information Disclosure vulnerability

Windows DHCP Server Information Disclosure vulnerability (CVE-2026-62814) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62813

Windows Active Directory Domain Services Remote Code Execution vulnerability

Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-62813) was added to Microsoft’s security update guidance. Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.