Microsoft security briefs
3324 published alerts for Microsoft products and services.
Microsoft PowerShell Remote Code Execution vulnerability
Microsoft PowerShell Remote Code Execution vulnerability (CVE-2026-50523) was added to Microsoft’s security update guidance. The security updates for Powershell have been updated. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-50313) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Microsoft Brokering File System Elevation of Privilege vulnerability
Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-49162) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Information Disclosure vulnerability
Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-48566) was added to Microsoft’s security update guidance. This CVE has been discovered to be an Elevation of Privilege and not an Information Disclosure. The CVE's Impact has been updated. If you need help checking exposure, call (864) 335-9223.
Windows Speech Runtime Elevation of Privilege vulnerability
Windows Speech Runtime Elevation of Privilege vulnerability (CVE-2026-32153) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Use after free in Blink in Microsoft Edge vulnerability
Use after free in Blink in Microsoft Edge vulnerability (CVE-2026-19560) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in HTML in Microsoft Edge vulnerability
Use after free in HTML in Microsoft Edge vulnerability (CVE-2026-19559) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Extensions in Microsoft Edge vulnerability
Use after free in Extensions in Microsoft Edge vulnerability (CVE-2026-19558) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in TabStrip in Microsoft Edge vulnerability
Use after free in TabStrip in Microsoft Edge vulnerability (CVE-2026-19557) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in V8 in Microsoft Edge vulnerability
Use after free in V8 in Microsoft Edge vulnerability (CVE-2026-19556) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution vulnerability
Microsoft Exchange Server Remote Code Execution vulnerability (CVE-2026-62913) was added to Microsoft’s security update guidance. Added acknowledgements. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Storage Elevation of Privilege vulnerability
Windows Storage Elevation of Privilege vulnerability (CVE-2026-62695) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows MIDI Service Module Elevation of Privileges vulnerability
Windows MIDI Service Module Elevation of Privileges vulnerability (CVE-2026-62688) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows Storage Elevation of Privilege vulnerability
Windows Storage Elevation of Privilege vulnerability (CVE-2026-61359) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows Graphics Kernel Elevation of Privilege vulnerability
Windows Graphics Kernel Elevation of Privilege vulnerability (CVE-2026-61346) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-50461) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows GDI Elevation of Privilege vulnerability
Windows GDI Elevation of Privilege vulnerability (CVE-2026-50387) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows MIDI Service Module Elevation of Privileges vulnerability
Windows MIDI Service Module Elevation of Privileges vulnerability (CVE-2026-50342) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-50309) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows Spaceport.sys Elevation of Privilege vulnerability
Windows Spaceport.sys Elevation of Privilege vulnerability (CVE-2026-50298) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-45638) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Microsoft DWM Core Library Elevation of Privilege vulnerability
Microsoft DWM Core Library Elevation of Privilege vulnerability (CVE-2026-45637) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege vulnerability
Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege vulnerability (CVE-2026-45597) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows SDK Elevation of Privilege vulnerability
Windows SDK Elevation of Privilege vulnerability (CVE-2026-45593) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.