Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-65774

Windows Installer Elevation of Privilege vulnerability

Windows Installer Elevation of Privilege vulnerability (CVE-2026-65774) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65773

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-65773) was added to Microsoft’s security update guidance. Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65767

Microsoft Teams for Android Spoofing vulnerability

Microsoft Teams for Android Spoofing vulnerability (CVE-2026-65767) was added to Microsoft’s security update guidance. Corrected build number for the security update. This in an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65681

Windows iSCSI Target Service Denial of Service vulnerability

Windows iSCSI Target Service Denial of Service vulnerability (CVE-2026-65681) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65680

Microsoft OneDrive for MacOS Elevation of Privilege vulnerability

Microsoft OneDrive for MacOS Elevation of Privilege vulnerability (CVE-2026-65680) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65679

Windows iSCSI Target Service Remote Code Execution vulnerability

Windows iSCSI Target Service Remote Code Execution vulnerability (CVE-2026-65679) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65678

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-65678) was added to Microsoft’s security update guidance. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65673

Microsoft Entra Connect Elevation of Privilege vulnerability

Microsoft Entra Connect Elevation of Privilege vulnerability (CVE-2026-65673) was added to Microsoft’s security update guidance. CVET-EOP If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65665

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-65665) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65664

Microsoft Office Graphics Component Remote Code Execution vulnerability

Microsoft Office Graphics Component Remote Code Execution vulnerability (CVE-2026-65664) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65663

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-65663) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65662

Windows GDI Information Disclosure vulnerability

Windows GDI Information Disclosure vulnerability (CVE-2026-65662) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65661

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-65661) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65658

Microsoft SharePoint Server Remote Code Execution vulnerability

Microsoft SharePoint Server Remote Code Execution vulnerability (CVE-2026-65658) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65657

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-65657) was added to Microsoft’s security update guidance. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65656

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-65656) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64922

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-64922) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64921

Microsoft SharePoint Server Elevation of Privilege vulnerability

Microsoft SharePoint Server Elevation of Privilege vulnerability (CVE-2026-64921) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64920

Microsoft Access Remote Code Execution vulnerability

Microsoft Access Remote Code Execution vulnerability (CVE-2026-64920) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64919

Microsoft Access Remote Code Execution vulnerability

Microsoft Access Remote Code Execution vulnerability (CVE-2026-64919) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64917

Microsoft Office Word Information Disclosure vulnerability

Microsoft Office Word Information Disclosure vulnerability (CVE-2026-64917) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64916

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-64916) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64915

Microsoft Office Word Remote Code Execution vulnerability

Microsoft Office Word Remote Code Execution vulnerability (CVE-2026-64915) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-64914

Microsoft Access Remote Code Execution vulnerability

Microsoft Access Remote Code Execution vulnerability (CVE-2026-64914) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.