Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-69558

Microsoft Partner Center Information Disclosure vulnerability

Microsoft Partner Center Information Disclosure vulnerability (CVE-2026-69558) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69555

Azure Arc Elevation of Privilege vulnerability

Azure Arc Elevation of Privilege vulnerability (CVE-2026-69555) was added to Microsoft’s security update guidance. <p>Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69543

Azure Virtual Machines Elevation of Privilege vulnerability

Azure Virtual Machines Elevation of Privilege vulnerability (CVE-2026-69543) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69519

Azure Stack HCI Information Disclosure vulnerability

Azure Stack HCI Information Disclosure vulnerability (CVE-2026-69519) was added to Microsoft’s security update guidance. <p>Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69502

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-69502) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69419

Azure Data Manager for Energy Remote Code Execution vulnerability

Azure Data Manager for Energy Remote Code Execution vulnerability (CVE-2026-69419) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-69400

Azure Logic Apps Elevation of Privilege vulnerability

Azure Logic Apps Elevation of Privilege vulnerability (CVE-2026-69400) was added to Microsoft’s security update guidance. <p>Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68789

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-68789) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68782

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-68782) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66800

Azure Data Factory Information Disclosure vulnerability

Azure Data Factory Information Disclosure vulnerability (CVE-2026-66800) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66309

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-66309) was added to Microsoft’s security update guidance. <p>Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65816

Azure Arc Elevation of Privilege vulnerability

Azure Arc Elevation of Privilege vulnerability (CVE-2026-65816) was added to Microsoft’s security update guidance. <p>Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65801

Microsoft Exchange Online Elevation of Privilege vulnerability

Microsoft Exchange Online Elevation of Privilege vulnerability (CVE-2026-65801) was added to Microsoft’s security update guidance. <p>Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65770

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability

Azure Managed Instance for Apache Cassandra Remote Code Execution vulnerability (CVE-2026-65770) was added to Microsoft’s security update guidance. <p>Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63509

Microsoft Fabric Elevation of Privilege vulnerability

Microsoft Fabric Elevation of Privilege vulnerability (CVE-2026-63509) was added to Microsoft’s security update guidance. <p>Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62834

Azure Data Factory Elevation of Privilege vulnerability

Azure Data Factory Elevation of Privilege vulnerability (CVE-2026-62834) was added to Microsoft’s security update guidance. <p>Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62755

Windows DHCP Client Elevation of Privilege vulnerability

Windows DHCP Client Elevation of Privilege vulnerability (CVE-2026-62755) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62754

Windows Kerberos Elevation of Privilege vulnerability

Windows Kerberos Elevation of Privilege vulnerability (CVE-2026-62754) was added to Microsoft’s security update guidance. Updated links to security updates. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62703

Windows DWM Core Library Information Disclosure vulnerability

Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-62703) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55015

Microsoft Remote Help Denial of Service vulnerability

Microsoft Remote Help Denial of Service vulnerability (CVE-2026-55015) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55013

Windows Remote Help Defense Spoofing vulnerability

Windows Remote Help Defense Spoofing vulnerability (CVE-2026-55013) was added to Microsoft’s security update guidance. <p>Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54118

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-54118) was added to Microsoft’s security update guidance. The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54117

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-54117) was added to Microsoft’s security update guidance. The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58647

Microsoft PowerBI Report Server Spoofing vulnerability

Microsoft PowerBI Report Server Spoofing vulnerability (CVE-2026-58647) was added to Microsoft’s security update guidance. Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only. If you need help checking exposure, call (864) 335-9223.