Microsoft security briefs
3324 published alerts for Microsoft products and services.
Microsoft SharePoint Server Information Disclosure vulnerability
Microsoft SharePoint Server Information Disclosure vulnerability (CVE-2026-62837) was added to Microsoft’s security update guidance. Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows User Profile Service Elevation of Privilege vulnerability
Windows User Profile Service Elevation of Privilege vulnerability (CVE-2026-62832) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-62829) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Elevation of Privilege vulnerability
Microsoft SharePoint Server Elevation of Privilege vulnerability (CVE-2026-62827) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows GDI+ Remote Code Execution vulnerability
Windows GDI+ Remote Code Execution vulnerability (CVE-2026-62822) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Certificate Services (AD CS) Remote Code Execution vulnerability
Windows Active Directory Certificate Services (AD CS) Remote Code Execution vulnerability (CVE-2026-62818) was added to Microsoft’s security update guidance. Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability (CVE-2026-62816) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Windows HTTP.sys Elevation of Privilege vulnerability
Windows HTTP.sys Elevation of Privilege vulnerability (CVE-2026-62811) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows SMBv3 Server Remote Code Execution vulnerability
Windows SMBv3 Server Remote Code Execution vulnerability (CVE-2026-62800) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-62797) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Information Disclosure vulnerability
Windows NTFS Information Disclosure vulnerability (CVE-2026-62796) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution vulnerability
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution vulnerability (CVE-2026-62795) was added to Microsoft’s security update guidance. Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Information Disclosure vulnerability
Windows NTFS Information Disclosure vulnerability (CVE-2026-62793) was added to Microsoft’s security update guidance. Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Remote Code Execution vulnerability
Windows TCP/IP Remote Code Execution vulnerability (CVE-2026-62792) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows SMBv3 Server Remote Code Execution vulnerability
Windows SMBv3 Server Remote Code Execution vulnerability (CVE-2026-62790) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-62788) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution vulnerability
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution vulnerability (CVE-2026-62785) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Local Security Authority Server (lsasrv) Remote Code Execution vulnerability
Microsoft Local Security Authority Server (lsasrv) Remote Code Execution vulnerability (CVE-2026-62784) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Remote Access Connection Manager Elevation of Privilege vulnerability
Windows Remote Access Connection Manager Elevation of Privilege vulnerability (CVE-2026-62783) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows SMB Client Information Disclosure vulnerability
Windows SMB Client Information Disclosure vulnerability (CVE-2026-62782) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-62780) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Schannel Elevation of Privilege vulnerability
Windows Schannel Elevation of Privilege vulnerability (CVE-2026-62779) was added to Microsoft’s security update guidance. Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DNS Elevation of Privilege vulnerability
Windows DNS Elevation of Privilege vulnerability (CVE-2026-62778) was added to Microsoft’s security update guidance. Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure vulnerability
Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure vulnerability (CVE-2026-62775) was added to Microsoft’s security update guidance. Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.