Microsoft security briefs
3324 published alerts for Microsoft products and services.
Windows Defender Firewall Service Security Feature Bypass vulnerability
Windows Defender Firewall Service Security Feature Bypass vulnerability (CVE-2026-61936) was added to Microsoft’s security update guidance. Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows Bind Filter Driver Elevation of Privilege vulnerability
Windows Bind Filter Driver Elevation of Privilege vulnerability (CVE-2026-61934) was added to Microsoft’s security update guidance. Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Information Disclosure vulnerability
Windows DWM Core Library Information Disclosure vulnerability (CVE-2026-61933) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows DWM Core Library Elevation of Privilege vulnerability
Windows DWM Core Library Elevation of Privilege vulnerability (CVE-2026-61932) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-61930) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-61929) was added to Microsoft’s security update guidance. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Hello Tampering vulnerability
Windows Hello Tampering vulnerability (CVE-2026-61928) was added to Microsoft’s security update guidance. Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. If you need help checking exposure, call (864) 335-9223.
Windows Bind Filter Driver Elevation of Privilege vulnerability
Windows Bind Filter Driver Elevation of Privilege vulnerability (CVE-2026-61927) was added to Microsoft’s security update guidance. Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows USB Driver Elevation of Privilege vulnerability
Windows USB Driver Elevation of Privilege vulnerability (CVE-2026-61926) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-61925) was added to Microsoft’s security update guidance. Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-61924) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-61921) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-61918) was added to Microsoft’s security update guidance. Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Hyper-V Information Disclosure vulnerability
Windows Hyper-V Information Disclosure vulnerability (CVE-2026-61368) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61367) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Network Connection Broker Elevation of Privilege vulnerability
Windows Network Connection Broker Elevation of Privilege vulnerability (CVE-2026-61366) was added to Microsoft’s security update guidance. Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61365) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61364) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Client Remote Code Execution vulnerability
Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-61361) was added to Microsoft’s security update guidance. Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows GDI Information Disclosure vulnerability
Windows GDI Information Disclosure vulnerability (CVE-2026-61360) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege vulnerability
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege vulnerability (CVE-2026-61358) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Elevation of Privilege vulnerability
Windows Remote Desktop Services Elevation of Privilege vulnerability (CVE-2026-61356) was added to Microsoft’s security update guidance. Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Sensor Data Service Elevation of Privilege vulnerability
Windows Sensor Data Service Elevation of Privilege vulnerability (CVE-2026-61355) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-61353) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.