Microsoft security briefs
3324 published alerts for Microsoft products and services.
Windows NTFS Information Disclosure vulnerability
Windows NTFS Information Disclosure vulnerability (CVE-2026-61350) was added to Microsoft’s security update guidance. Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. If you need help checking exposure, call (864) 335-9223.
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-61348) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Remote Registry Service Denial of Service vulnerability
Microsoft Remote Registry Service Denial of Service vulnerability (CVE-2026-61345) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Microsoft Remote Registry Service Denial of Service vulnerability
Microsoft Remote Registry Service Denial of Service vulnerability (CVE-2026-59138) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Windows Event Logging Service Information Disclosure vulnerability
Windows Event Logging Service Information Disclosure vulnerability (CVE-2026-59137) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft COM for Windows Information Disclosure vulnerability
Microsoft COM for Windows Information Disclosure vulnerability (CVE-2026-59136) was added to Microsoft’s security update guidance. Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Search Component Information Disclosure vulnerability
Microsoft Windows Search Component Information Disclosure vulnerability (CVE-2026-59135) was added to Microsoft’s security update guidance. Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege vulnerability
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege vulnerability (CVE-2026-59133) was added to Microsoft’s security update guidance. Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows TCP/IP Denial of Service vulnerability
Windows TCP/IP Denial of Service vulnerability (CVE-2026-59132) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.
Windows Encrypting File System (EFS) Information Disclosure vulnerability
Windows Encrypting File System (EFS) Information Disclosure vulnerability (CVE-2026-59128) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows Telephony Service Elevation of Privilege vulnerability
Windows Telephony Service Elevation of Privilege vulnerability (CVE-2026-59122) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-58651) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-58639) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office SharePoint Spoofing vulnerability
Microsoft Office SharePoint Spoofing vulnerability (CVE-2026-57105) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Azure Storage Explorer Elevation of Privilege vulnerability
Azure Storage Explorer Elevation of Privilege vulnerability (CVE-2026-57104) was added to Microsoft’s security update guidance. Corrected build number for the security update. This in an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Network Address Translation (NAT) Spoofing vulnerability
Windows Network Address Translation (NAT) Spoofing vulnerability (CVE-2026-56179) was added to Microsoft’s security update guidance. Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. If you need help checking exposure, call (864) 335-9223.
Windows Narrator Braille Elevation of Privilege vulnerability
Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-56174) was added to Microsoft’s security update guidance. Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Imaging Component Remote Code Execution vulnerability
Windows Imaging Component Remote Code Execution vulnerability (CVE-2026-54984) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability
Microsoft Defender for Endpoint for Mac Information Disclosure vulnerability (CVE-2026-54123) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability
Windows LUA File Virtualization Filter Driver Elevation of Privilege vulnerability (CVE-2026-50472) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Domain Services Remote Code Execution vulnerability
Windows Active Directory Domain Services Remote Code Execution vulnerability (CVE-2026-49179) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Azure Monitor Agent Elevation of Privilege vulnerability
Azure Monitor Agent Elevation of Privilege vulnerability (CVE-2026-47299) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics Business Central Information Disclosure vulnerability
Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2026-40375) was added to Microsoft’s security update guidance. Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50357) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.