Microsoft security briefs
3324 published alerts for Microsoft products and services.
Windows Internet (wininet.dll) Elevation of Privilege vulnerability
Windows Internet (wininet.dll) Elevation of Privilege vulnerability (CVE-2026-45592) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Management Services Denial of Service vulnerability
Windows Management Services Denial of Service vulnerability (CVE-2026-70348) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-68815) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Program Compatibility Assistant Service Elevation of Privilege vulnerability
Windows Program Compatibility Assistant Service Elevation of Privilege vulnerability (CVE-2026-62696) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Admin Center Spoofing vulnerability
Windows Admin Center Spoofing vulnerability (CVE-2026-58643) was added to Microsoft’s security update guidance. Corrected Build Number in the Security Updates table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Bluetooth Service Elevation of Privilege vulnerability
Windows Bluetooth Service Elevation of Privilege vulnerability (CVE-2026-58538) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-50687) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Media Foundation Remote Code Execution vulnerability
Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-50655) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Network Connections Service Elevation of Privilege vulnerability
Windows Network Connections Service Elevation of Privilege vulnerability (CVE-2026-50476) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Insufficient validation of untrusted input in Microsoft Edge vulnerability
Insufficient validation of untrusted input in Microsoft Edge vulnerability (CVE-2026-19177) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution vulnerability
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution vulnerability (CVE-2022-41127) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering vulnerability
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering vulnerability (CVE-2026-72971) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. If you need help checking exposure, call (864) 335-9223.
Windows Device Health Attestation (DHA) Remote Code Execution vulnerability
Windows Device Health Attestation (DHA) Remote Code Execution vulnerability (CVE-2026-71331) was added to Microsoft’s security update guidance. Updated links to security updates. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Elevation of Privilege vulnerability
Microsoft SharePoint Server Elevation of Privilege vulnerability (CVE-2026-70355) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-70347) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-70346) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-70345) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-70344) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Azure CycleCloud Elevation of Privilege vulnerability
Azure CycleCloud Elevation of Privilege vulnerability (CVE-2026-70340) was added to Microsoft’s security update guidance. Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution vulnerability (CVE-2026-70339) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft PowerShell Security Feature Bypass vulnerability
Microsoft PowerShell Security Feature Bypass vulnerability (CVE-2026-70338) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Microsoft PowerShell Remote Code Execution vulnerability
Microsoft PowerShell Remote Code Execution vulnerability (CVE-2026-70337) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-70330) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Information Disclosure vulnerability
Microsoft Excel Information Disclosure vulnerability (CVE-2026-70328) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.