Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-50515

Azure Service Bus Remote Code Execution vulnerability

Azure Service Bus Remote Code Execution vulnerability (CVE-2026-50515) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50481

Azure Active Directory Elevation of Privilege vulnerability

Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-50481) was added to Microsoft’s security update guidance. Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50341

Windows NTFS Information Disclosure vulnerability

Windows NTFS Information Disclosure vulnerability (CVE-2026-50341) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66803

Azure Cosmos DB Remote Code Execution vulnerability

Azure Cosmos DB Remote Code Execution vulnerability (CVE-2026-66803) was added to Microsoft’s security update guidance. Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56197

Windows Admin Center (WAC) Remote Code Execution vulnerability

Windows Admin Center (WAC) Remote Code Execution vulnerability (CVE-2026-56197) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55129

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55129) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54128

Windows DHCP Client Remote Code Execution vulnerability

Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-54128) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-24304

Azure Resource Manager Elevation of Privilege vulnerability

Azure Resource Manager Elevation of Privilege vulnerability (CVE-2026-24304) was added to Microsoft’s security update guidance. Informational Change. CVE ID stays the same. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-59117

Windows Terminal Remote Code Execution vulnerability

Windows Terminal Remote Code Execution vulnerability (CVE-2026-59117) was added to Microsoft’s security update guidance. Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50422

Windows NTFS Elevation of Privilege vulnerability

Windows NTFS Elevation of Privilege vulnerability (CVE-2026-50422) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13037

Use after free in WebView in Microsoft Edge vulnerability

Use after free in WebView in Microsoft Edge vulnerability (CVE-2026-13037) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13032

Use after free in WebGL in Microsoft Edge vulnerability

Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-13032) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13030

Uninitialized Use in GPU in Microsoft Edge vulnerability

Uninitialized Use in GPU in Microsoft Edge vulnerability (CVE-2026-13030) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-13028

Use after free in WebGL in Microsoft Edge vulnerability

Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-13028) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50697

Windows Common Log File System Driver Elevation of Privilege vulnerability

Windows Common Log File System Driver Elevation of Privilege vulnerability (CVE-2026-50697) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50343

Microsoft Install Service Elevation of Privilege vulnerability

Microsoft Install Service Elevation of Privilege vulnerability (CVE-2026-50343) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-16807

Out of bounds write in Codecs in Microsoft Edge vulnerability

Out of bounds write in Codecs in Microsoft Edge vulnerability (CVE-2026-16807) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-16806

Use after free in WebMCP in Microsoft Edge vulnerability

Use after free in WebMCP in Microsoft Edge vulnerability (CVE-2026-16806) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-16805

Use after free in Blink in Microsoft Edge vulnerability

Use after free in Blink in Microsoft Edge vulnerability (CVE-2026-16805) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-16804

Use after free in Input in Microsoft Edge vulnerability

Use after free in Input in Microsoft Edge vulnerability (CVE-2026-16804) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62835

Azure Portal Information Disclosure vulnerability

Azure Portal Information Disclosure vulnerability (CVE-2026-62835) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-48561

Microsoft Edge Copilot Remote Code Execution vulnerability

Microsoft Edge Copilot Remote Code Execution vulnerability (CVE-2026-48561) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-62825

Azure Key Vault Elevation of Privilege vulnerability

Azure Key Vault Elevation of Privilege vulnerability (CVE-2026-62825) was added to Microsoft’s security update guidance. Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58630

Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability

Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability (CVE-2026-58630) was added to Microsoft’s security update guidance. Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.