Microsoft security briefs
3323 published alerts for Microsoft products and services.
Windows App for Mac Information Disclosure vulnerability
Windows App for Mac Information Disclosure vulnerability (CVE-2026-69550) was added to Microsoft’s security update guidance. Updated CWE value. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Cross Device Service Elevation of Privilege vulnerability
Microsoft Windows Cross Device Service Elevation of Privilege vulnerability (CVE-2026-66804) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-65660) was added to Microsoft’s security update guidance. Updated Impact in the Security Updates table, CVE Title, and FAQs. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Overlay Filter Elevation of Privilege vulnerability
Windows Overlay Filter Elevation of Privilege vulnerability (CVE-2026-50435) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Network File System Denial of Service vulnerability
Windows Network File System Denial of Service vulnerability (CVE-2026-68819) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows GDI+ Elevation of Privilege vulnerability
Windows GDI+ Elevation of Privilege vulnerability (CVE-2026-62890) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1068). Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. CISA remediation due date: 2026-08-29. If you need help checking exposure, call (864) 335-9223.
Windows Common Log File System Driver Elevation of Privilege vulnerability
Windows Common Log File System Driver Elevation of Privilege vulnerability (CVE-2026-62728) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-59127) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55137) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Elevation of Privilege vulnerability
Windows Spaceport.sys Elevation of Privilege vulnerability (CVE-2026-50333) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Clipboard Server Elevation of Privilege vulnerability
Windows Clipboard Server Elevation of Privilege vulnerability (CVE-2026-49183) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-45639) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows BitLocker Security Feature Bypass vulnerability
Windows BitLocker Security Feature Bypass vulnerability (CVE-2026-50661) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Visual Studio Code MSSQL Extension Remote Code Execution vulnerability
Visual Studio Code MSSQL Extension Remote Code Execution vulnerability (CVE-2026-47292) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-64903) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege vulnerability
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege vulnerability (CVE-2026-58547) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Visual Studio Code Python Extension Security Feature Bypass vulnerability
Visual Studio Code Python Extension Security Feature Bypass vulnerability (CVE-2026-54981) was added to Microsoft’s security update guidance. Affected software updated with new package information. If you need help checking exposure, call (864) 335-9223.
Microsoft Brokering File System Elevation of Privilege vulnerability
Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-50466) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Shell Spoofing vulnerability
Windows Shell Spoofing vulnerability (CVE-2026-32202) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Information Disclosure vulnerability
Microsoft Word Information Disclosure vulnerability (CVE-2026-70105) was added to Microsoft’s security update guidance. Information published. This CVE was addressed by updates that were released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who have already installed the August 2026 updates do not ne… If you need help checking exposure, call (864) 335-9223.
Azure Information Disclosure Vulnerability
Azure Information Disclosure Vulnerability (CVE-2026-69855) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Entra ID Elevation of Privilege vulnerability
Microsoft Entra ID Elevation of Privilege vulnerability (CVE-2026-69851) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Entra ID Remote Code Execution vulnerability
Microsoft Entra ID Remote Code Execution vulnerability (CVE-2026-69836) was added to Microsoft’s security update guidance. Corrected **Exploited** to **No**. This vulnerability was not exploited in the wild. This is an informational change only. If you need help checking exposure, call (864) 335-9223.