Microsoft Edge for Android Information Disclosure vulnerability
Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58296) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Edge for Android Information Disclosure vulnerability
Microsoft Edge for Android Information Disclosure vulnerability (CVE-2026-58297) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Edge (Chromium-based) Spoofing vulnerability
Microsoft Edge (Chromium-based) Spoofing vulnerability (CVE-2026-58298) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Resource Manager Elevation of Privilege vulnerability
Azure Resource Manager Elevation of Privilege vulnerability (CVE-2026-24304) was added to Microsoft’s security update guidance. Informational Change. CVE ID stays the same. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Cosmos DB Remote Code Execution vulnerability
Azure Cosmos DB Remote Code Execution vulnerability (CVE-2026-66803) was added to Microsoft’s security update guidance. Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Portal Information Disclosure vulnerability
Azure Portal Information Disclosure vulnerability (CVE-2026-62835) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure API Management (APIM) Remote Code Execution vulnerability
Azure API Management (APIM) Remote Code Execution vulnerability (CVE-2026-35425) was added to Microsoft’s security update guidance. Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Graph Information Disclosure vulnerability
Microsoft Graph Information Disclosure vulnerability (CVE-2026-49159) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft M365 Copilot Remote Code Execution vulnerability
Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-50517) was added to Microsoft’s security update guidance. Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Surface Remote Code Execution vulnerability
Microsoft Surface Remote Code Execution vulnerability (CVE-2026-54120) was added to Microsoft’s security update guidance. Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability
Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability (CVE-2026-56160) was added to Microsoft’s security update guidance. Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability
Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-56163) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Account Remote Code Execution vulnerability
Microsoft Account Remote Code Execution vulnerability (CVE-2026-56165) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure AI Search Elevation of Privilege vulnerability
Azure AI Search Elevation of Privilege vulnerability (CVE-2026-56167) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Microsoft Exchange Online Tampering vulnerability
Microsoft Exchange Online Tampering vulnerability (CVE-2026-56191) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure DNS Elevation of Privilege vulnerability
Azure DNS Elevation of Privilege vulnerability (CVE-2026-58275) was added to Microsoft’s security update guidance. Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability
Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability (CVE-2026-58630) was added to Microsoft’s security update guidance. Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Azure Key Vault Elevation of Privilege vulnerability
Azure Key Vault Elevation of Privilege vulnerability (CVE-2026-62825) was added to Microsoft’s security update guidance. Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability
Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability (CVE-2026-58529) was added to Microsoft’s security update guidance. Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows SMB Elevation of Privilege vulnerability
Windows SMB Elevation of Privilege vulnerability (CVE-2026-58531) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-58532) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58533) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Input Method Editor (IME) Elevation of Privilege vulnerability
Windows Input Method Editor (IME) Elevation of Privilege vulnerability (CVE-2026-58534) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58535) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.