Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-66799

Windows Key Guard Elevation of Privilege vulnerability

Windows Key Guard Elevation of Privilege vulnerability (CVE-2026-66799) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66301

Microsoft Dynamics 365 (On-Premises) Information Disclosure vulnerability

Microsoft Dynamics 365 (On-Premises) Information Disclosure vulnerability (CVE-2026-66301) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65815

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability

Microsoft Dynamics 365 On-Premises Remote Code Execution vulnerability (CVE-2026-65815) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65814

Microsoft Windows Storage Port Driver Elevation of Privilege vulnerability

Microsoft Windows Storage Port Driver Elevation of Privilege vulnerability (CVE-2026-65814) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65807

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-65807) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65806

Azure CycleCloud Information Disclosure vulnerability

Azure CycleCloud Information Disclosure vulnerability (CVE-2026-65806) was added to Microsoft’s security update guidance. Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65799

Windows DNS Elevation of Privilege vulnerability

Windows DNS Elevation of Privilege vulnerability (CVE-2026-65799) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65798

Windows DNS Elevation of Privilege vulnerability

Windows DNS Elevation of Privilege vulnerability (CVE-2026-65798) was added to Microsoft’s security update guidance. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65797

Windows DNS Elevation of Privilege vulnerability

Windows DNS Elevation of Privilege vulnerability (CVE-2026-65797) was added to Microsoft’s security update guidance. Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65796

Windows iSCSI Target Service Remote Code Execution vulnerability

Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65796) was added to Microsoft’s security update guidance. Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates table. These are i… If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65795

Windows DNS Elevation of Privilege vulnerability

Windows DNS Elevation of Privilege vulnerability (CVE-2026-65795) was added to Microsoft’s security update guidance. No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65794

Windows SMB Client Information Disclosure vulnerability

Windows SMB Client Information Disclosure vulnerability (CVE-2026-65794) was added to Microsoft’s security update guidance. Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65791

Windows iSCSI Target Service Remote Code Execution vulnerability

Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65791) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65790

Windows Message Queuing Elevation of Privilege vulnerability

Windows Message Queuing Elevation of Privilege vulnerability (CVE-2026-65790) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65785

Windows DHCP Client Denial of Service vulnerability

Windows DHCP Client Denial of Service vulnerability (CVE-2026-65785) was added to Microsoft’s security update guidance. Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65784

Windows NTFS Information Disclosure vulnerability

Windows NTFS Information Disclosure vulnerability (CVE-2026-65784) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65783

Windows Autopilot Elevation of Privilege vulnerability

Windows Autopilot Elevation of Privilege vulnerability (CVE-2026-65783) was added to Microsoft’s security update guidance. Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65782

Windows Autopilot Elevation of Privilege vulnerability

Windows Autopilot Elevation of Privilege vulnerability (CVE-2026-65782) was added to Microsoft’s security update guidance. Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65781

Windows Autopilot Elevation of Privilege vulnerability

Windows Autopilot Elevation of Privilege vulnerability (CVE-2026-65781) was added to Microsoft’s security update guidance. Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65780

Windows Autopilot Elevation of Privilege vulnerability

Windows Autopilot Elevation of Privilege vulnerability (CVE-2026-65780) was added to Microsoft’s security update guidance. Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65779

Windows Autopilot Elevation of Privilege vulnerability

Windows Autopilot Elevation of Privilege vulnerability (CVE-2026-65779) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65778

Windows Autopilot Elevation of Privilege vulnerability

Windows Autopilot Elevation of Privilege vulnerability (CVE-2026-65778) was added to Microsoft’s security update guidance. Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65776

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-65776) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65775

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-65775) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.