Microsoft security briefs
3324 published alerts for Microsoft products and services.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-65774) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-65773) was added to Microsoft’s security update guidance. Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Teams for Android Spoofing vulnerability
Microsoft Teams for Android Spoofing vulnerability (CVE-2026-65767) was added to Microsoft’s security update guidance. Corrected build number for the security update. This in an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Target Service Denial of Service vulnerability
Windows iSCSI Target Service Denial of Service vulnerability (CVE-2026-65681) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Microsoft OneDrive for MacOS Elevation of Privilege vulnerability
Microsoft OneDrive for MacOS Elevation of Privilege vulnerability (CVE-2026-65680) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows iSCSI Target Service Remote Code Execution vulnerability
Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65679) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Win32k Elevation of Privilege vulnerability
Windows Win32k Elevation of Privilege vulnerability (CVE-2026-65678) was added to Microsoft’s security update guidance. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Entra Connect Elevation of Privilege vulnerability
Microsoft Entra Connect Elevation of Privilege vulnerability (CVE-2026-65673) was added to Microsoft’s security update guidance. CVET-EOP If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-65665) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Graphics Component Remote Code Execution vulnerability
Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-65664) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-65663) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows GDI Information Disclosure vulnerability
Windows GDI Information Disclosure vulnerability (CVE-2026-65662) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-65661) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Remote Code Execution vulnerability
Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-65658) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-65657) was added to Microsoft’s security update guidance. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-65656) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-64922) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Elevation of Privilege vulnerability
Microsoft SharePoint Server Elevation of Privilege vulnerability (CVE-2026-64921) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Access Remote Code Execution vulnerability
Microsoft Access Remote Code Execution vulnerability (CVE-2026-64920) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Access Remote Code Execution vulnerability
Microsoft Access Remote Code Execution vulnerability (CVE-2026-64919) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Information Disclosure vulnerability
Microsoft Office Word Information Disclosure vulnerability (CVE-2026-64917) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-64916) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Word Remote Code Execution vulnerability
Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-64915) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Access Remote Code Execution vulnerability
Microsoft Access Remote Code Execution vulnerability (CVE-2026-64914) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.