Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows Print Spooler Information Disclosure vulnerability
Windows Print Spooler Information Disclosure vulnerability (CVE-2026-57085) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Trace Data Helper Elevation of Privilege vulnerability
Microsoft Trace Data Helper Elevation of Privilege vulnerability (CVE-2026-56198) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Server Elevation of Privilege vulnerability
Windows Server Elevation of Privilege vulnerability (CVE-2026-56177) was added to Microsoft’s security update guidance. <p>Use after free in Windows Server allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows VHD miniport driver Elevation of Privilege vulnerability
Windows VHD miniport driver Elevation of Privilege vulnerability (CVE-2026-56172) was added to Microsoft’s security update guidance. <p>Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution vulnerability
Microsoft Exchange Server Remote Code Execution vulnerability (CVE-2026-55007) was added to Microsoft’s security update guidance. Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class Driver Information Disclosure vulnerability
Windows USB Audio Class Driver Information Disclosure vulnerability (CVE-2026-50453) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-50349) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-47297) was added to Microsoft’s security update guidance. Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Information Disclosure vulnerability
Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-44814) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Denial of Service vulnerability
Windows Kerberos Denial of Service vulnerability (CVE-2026-42914) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-50376) was added to Microsoft’s security update guidance. Acknowledgment updated If you need help checking exposure, call (864) 335-9223.
Microsoft QUIC Remote Code Execution vulnerability
Microsoft QUIC Remote Code Execution vulnerability (CVE-2026-62815) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Remote Code Execution vulnerability
Visual Studio Code Remote Code Execution vulnerability (CVE-2026-70336) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Remote Code Execution vulnerability
Visual Studio Code Remote Code Execution vulnerability (CVE-2026-69320) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-69306) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-69278) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-62880) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-62768) was added to Microsoft’s security update guidance. Acknowledgement added. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Remote Code Execution vulnerability
Visual Studio Code Remote Code Execution vulnerability (CVE-2026-59113) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Security Feature Bypass vulnerability
Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-58650) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Information Disclosure vulnerability
Visual Studio Code Information Disclosure vulnerability (CVE-2026-47285) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-64899) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution vulnerability (CVE-2026-62889) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-55134) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.