Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-40417

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2026-40417) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2025-29821

Microsoft Dynamics Business Central Information Disclosure vulnerability

Microsoft Dynamics Business Central Information Disclosure vulnerability (CVE-2025-29821) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2024-38225

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-38225) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2024-21380

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability

Microsoft Dynamics Business Central/NAV Information Disclosure vulnerability (CVE-2024-21380) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2021-40440

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-40440) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2021-36946

Microsoft Dynamics Business Central Cross-site Scripting vulnerability

Microsoft Dynamics Business Central Cross-site Scripting vulnerability (CVE-2021-36946) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2021-34474

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability

Microsoft Dynamics 365 Business Central Remote Code Execution vulnerability (CVE-2021-34474) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-70332

Microsoft Office SharePoint Spoofing vulnerability

Microsoft Office SharePoint Spoofing vulnerability (CVE-2026-70332) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-68823

Azure Confidential Ledger Remote Code Execution vulnerability

Azure Confidential Ledger Remote Code Execution vulnerability (CVE-2026-68823) was added to Microsoft’s security update guidance. Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65668

Microsoft Purview eDiscovery Elevation of Privilege vulnerability

Microsoft Purview eDiscovery Elevation of Privilege vulnerability (CVE-2026-65668) was added to Microsoft’s security update guidance. Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-65667

Microsoft Teams Elevation of Privilege vulnerability

Microsoft Teams Elevation of Privilege vulnerability (CVE-2026-65667) was added to Microsoft’s security update guidance. Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63522

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-63522) was added to Microsoft’s security update guidance. Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62918

Microsoft Teams Spoofing vulnerability

Microsoft Teams Spoofing vulnerability (CVE-2026-62918) was added to Microsoft’s security update guidance. Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62896

Microsoft Teams Elevation of Privilege vulnerability

Microsoft Teams Elevation of Privilege vulnerability (CVE-2026-62896) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62873

Microsoft 365 Admin Center Elevation of Privilege vulnerability

Microsoft 365 Admin Center Elevation of Privilege vulnerability (CVE-2026-62873) was added to Microsoft’s security update guidance. Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62869

Azure Entra ID Spoofing vulnerability

Azure Entra ID Spoofing vulnerability (CVE-2026-62869) was added to Microsoft’s security update guidance. Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62836

Azure SQL Managed Instance Elevation of Privilege vulnerability

Azure SQL Managed Instance Elevation of Privilege vulnerability (CVE-2026-62836) was added to Microsoft’s security update guidance. Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62830

Azure SRE Agent Elevation of Privilege vulnerability

Azure SRE Agent Elevation of Privilege vulnerability (CVE-2026-62830) was added to Microsoft’s security update guidance. Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59118

Microsoft Power Apps Elevation of Privilege vulnerability

Microsoft Power Apps Elevation of Privilege vulnerability (CVE-2026-59118) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59115

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability

Microsoft Entra Provisioning Service Elevation of Privilege vulnerability (CVE-2026-59115) was added to Microsoft’s security update guidance. '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56162

Azure SQL Database Elevation of Privilege vulnerability

Azure SQL Database Elevation of Privilege vulnerability (CVE-2026-56162) was added to Microsoft’s security update guidance. Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56161

Azure Logic Apps Information Disclosure vulnerability

Azure Logic Apps Information Disclosure vulnerability (CVE-2026-56161) was added to Microsoft’s security update guidance. Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55050

Microsoft Word Information Disclosure vulnerability

Microsoft Word Information Disclosure vulnerability (CVE-2026-55050) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50516

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-50516) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.