Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-61936

Windows Defender Firewall Service Security Feature Bypass vulnerability

Windows Defender Firewall Service Security Feature Bypass vulnerability (CVE-2026-61936) was added to Microsoft’s security update guidance. Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61934

Windows Bind Filter Driver Elevation of Privilege vulnerability

Windows Bind Filter Driver Elevation of Privilege vulnerability (CVE-2026-61934) was added to Microsoft’s security update guidance. Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61933

Windows DWM Core Library Information Disclosure vulnerability

Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-61933) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61932

Windows DWM Core Library Elevation of Privilege vulnerability

Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-61932) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61930

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-61930) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61929

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-61929) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61928

Windows Hello Tampering vulnerability

Windows Hello Tampering vulnerability (CVE-2026-61928) was added to Microsoft’s security update guidance. Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61927

Windows Bind Filter Driver Elevation of Privilege vulnerability

Windows Bind Filter Driver Elevation of Privilege vulnerability (CVE-2026-61927) was added to Microsoft’s security update guidance. Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61926

Windows USB Driver Elevation of Privilege vulnerability

Windows USB Driver Elevation of Privilege vulnerability (CVE-2026-61926) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61925

Windows Installer Elevation of Privilege vulnerability

Windows Installer Elevation of Privilege vulnerability (CVE-2026-61925) was added to Microsoft’s security update guidance. Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61924

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-61924) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61921

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-61921) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61918

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-61918) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61368

Windows Hyper-V Information Disclosure vulnerability

Windows Hyper-V Information Disclosure vulnerability (CVE-2026-61368) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61367

Windows Remote Desktop Services Elevation of Privilege vulnerability

Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61367) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61366

Windows Network Connection Broker Elevation of Privilege vulnerability

Windows Network Connection Broker Elevation of Privilege vulnerability (CVE-2026-61366) was added to Microsoft’s security update guidance. Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61365

Windows Remote Desktop Services Elevation of Privilege vulnerability

Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61365) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61364

Windows Remote Desktop Services Elevation of Privilege vulnerability

Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61364) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61361

Windows DHCP Client Remote Code Execution vulnerability

Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-61361) was added to Microsoft’s security update guidance. Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61360

Windows GDI Information Disclosure vulnerability

Windows GDI Information Disclosure vulnerability (CVE-2026-61360) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61358

Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege vulnerability

Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege vulnerability (CVE-2026-61358) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61356

Windows Remote Desktop Services Elevation of Privilege vulnerability

Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61356) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61355

Windows Sensor Data Service Elevation of Privilege vulnerability

Windows Sensor Data Service Elevation of Privilege vulnerability (CVE-2026-61355) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-61353

Windows Telephony Service Elevation of Privilege vulnerability

Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-61353) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.