Microsoft security briefs
3323 published alerts for Microsoft products and services.
Microsoft SQL Server Elevation of Privilege vulnerability
Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-66814) was added to Microsoft’s security update guidance. <p>Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business and Lync Denial of Service vulnerability
Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66308) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business and Lync Denial of Service vulnerability
Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66307) was added to Microsoft’s security update guidance. <p>Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business Information Disclosure vulnerability
Skype for Business Information Disclosure vulnerability (CVE-2026-66306) was added to Microsoft’s security update guidance. <p>Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business Spoofing vulnerability
Skype for Business Spoofing vulnerability (CVE-2026-66305) was added to Microsoft’s security update guidance. Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Skype for Business Information Disclosure vulnerability
Skype for Business Information Disclosure vulnerability (CVE-2026-66304) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business and Lync Denial of Service vulnerability
Skype for Business and Lync Denial of Service vulnerability (CVE-2026-66303) was added to Microsoft’s security update guidance. <p>Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.
Skype for Business Remote Code Execution vulnerability
Skype for Business Remote Code Execution vulnerability (CVE-2026-66302) was added to Microsoft’s security update guidance. <p>External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Teams for Android Information Disclosure vulnerability
Microsoft Teams for Android Information Disclosure vulnerability (CVE-2026-65812) was added to Microsoft’s security update guidance. Corrected fix build number. Informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-65789) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-65772) was added to Microsoft’s security update guidance. <p>Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Elevation of Privilege vulnerability
Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-65669) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Office Spoofing vulnerability
Microsoft Office Spoofing vulnerability (CVE-2026-64918) was added to Microsoft’s security update guidance. Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Skype for Business Spoofing vulnerability
Skype for Business Spoofing vulnerability (CVE-2026-63523) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Entra ID Elevation of Privilege vulnerability
Microsoft Entra ID Elevation of Privilege vulnerability (CVE-2026-62916) was added to Microsoft’s security update guidance. <p>Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Discovery Studio Information Disclosure vulnerability
Microsoft Discovery Studio Information Disclosure vulnerability (CVE-2026-62906) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Arc SQL Server Extension Elevation of Privilege vulnerability
Azure Arc SQL Server Extension Elevation of Privilege vulnerability (CVE-2026-62895) was added to Microsoft’s security update guidance. <p>Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows Deployment Services TFTP Server Remote Code Execution vulnerability
Windows Deployment Services TFTP Server Remote Code Execution vulnerability (CVE-2026-62893) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-62878) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Remote Code Execution vulnerability
Windows DHCP Server Remote Code Execution vulnerability (CVE-2026-62823) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-62820) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DNS Server Remote Code Execution vulnerability
Windows DNS Server Remote Code Execution vulnerability (CVE-2026-62817) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Information Disclosure vulnerability
Windows DHCP Server Information Disclosure vulnerability (CVE-2026-62814) was added to Microsoft’s security update guidance. Updated software table to remove clients versions because this vulnerability only impacts Windows Servers. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Domain Services Remote Code Execution vulnerability
Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-62813) was added to Microsoft’s security update guidance. Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.