Microsoft security briefs
3323 published alerts for Microsoft products and services.
Microsoft Partner Center Information Disclosure vulnerability
Microsoft Partner Center Information Disclosure vulnerability (CVE-2026-69558) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Arc Elevation of Privilege vulnerability
Azure Arc Elevation of Privilege vulnerability (CVE-2026-69555) was added to Microsoft’s security update guidance. <p>Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Virtual Machines Elevation of Privilege vulnerability
Azure Virtual Machines Elevation of Privilege vulnerability (CVE-2026-69543) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Stack HCI Information Disclosure vulnerability
Azure Stack HCI Information Disclosure vulnerability (CVE-2026-69519) was added to Microsoft’s security update guidance. <p>Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure SQL Database Elevation of Privilege vulnerability
Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-69502) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Data Manager for Energy Remote Code Execution vulnerability
Azure Data Manager for Energy Remote Code Execution vulnerability (CVE-2026-69419) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Logic Apps Elevation of Privilege vulnerability
Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-69400) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure SQL Database Elevation of Privilege vulnerability
Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-68789) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure SQL Database Elevation of Privilege vulnerability
Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-68782) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Data Factory Information Disclosure vulnerability
Azure Data Factory Information Disclosure vulnerability (CVE-2026-66800) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure SQL Database Elevation of Privilege vulnerability
Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-66309) was added to Microsoft’s security update guidance. <p>Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Arc Elevation of Privilege vulnerability
Azure Arc Elevation of Privilege vulnerability (CVE-2026-65816) was added to Microsoft’s security update guidance. <p>Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Online Elevation of Privilege vulnerability
Microsoft Exchange Online Elevation of Privilege vulnerability (CVE-2026-65801) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability
Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-65770) was added to Microsoft’s security update guidance. <p>Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft Fabric Elevation of Privilege vulnerability
Microsoft Fabric Elevation of Privilege vulnerability (CVE-2026-63509) was added to Microsoft’s security update guidance. <p>Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Azure Data Factory Elevation of Privilege vulnerability
Azure Data Factory Elevation of Privilege vulnerability (CVE-2026-62834) was added to Microsoft’s security update guidance. <p>Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.
Windows DHCP Client Elevation of Privilege vulnerability
Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-62755) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kerberos Elevation of Privilege vulnerability
Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62754) was added to Microsoft’s security update guidance. Updated links to security updates. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Information Disclosure vulnerability
Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-62703) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Remote Help Denial of Service vulnerability
Microsoft Remote Help Denial of Service vulnerability (CVE-2026-55015) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.</p> If you need help checking exposure, call (864) 335-9223.
Windows Remote Help Defense Spoofing vulnerability
Windows Remote Help Defense Spoofing vulnerability (CVE-2026-55013) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.</p> If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-54118) was added to Microsoft’s security update guidance. The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Remote Code Execution vulnerability
Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-54117) was added to Microsoft’s security update guidance. The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft PowerBI Report Server Spoofing vulnerability
Microsoft PowerBI Report Server Spoofing vulnerability (CVE-2026-58647) was added to Microsoft’s security update guidance. Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. If you need help checking exposure, call (864) 335-9223.