Microsoft security briefs
3324 published alerts for Microsoft products and services.
Azure Service Bus Remote Code Execution vulnerability
Azure Service Bus Remote Code Execution vulnerability (CVE-2026-50515) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Azure Active Directory Elevation of Privilege vulnerability
Azure Active Directory Elevation of Privilege vulnerability (CVE-2026-50481) was added to Microsoft’s security update guidance. Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Information Disclosure vulnerability
Windows NTFS Information Disclosure vulnerability (CVE-2026-50341) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Azure Cosmos DB Remote Code Execution vulnerability
Azure Cosmos DB Remote Code Execution vulnerability (CVE-2026-66803) was added to Microsoft’s security update guidance. Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Admin Center (WAC) Remote Code Execution vulnerability
Windows Admin Center (WAC) Remote Code Execution vulnerability (CVE-2026-56197) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-55129) was added to Microsoft’s security update guidance. Acknowledgement Updated If you need help checking exposure, call (864) 335-9223.
Windows DHCP Client Remote Code Execution vulnerability
Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-54128) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Azure Resource Manager Elevation of Privilege vulnerability
Azure Resource Manager Elevation of Privilege vulnerability (CVE-2026-24304) was added to Microsoft’s security update guidance. Informational Change. CVE ID stays the same. If you need help checking exposure, call (864) 335-9223.
Windows Terminal Remote Code Execution vulnerability
Windows Terminal Remote Code Execution vulnerability (CVE-2026-59117) was added to Microsoft’s security update guidance. Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-50422) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Use after free in WebView in Microsoft Edge vulnerability
Use after free in WebView in Microsoft Edge vulnerability (CVE-2026-13037) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in WebGL in Microsoft Edge vulnerability
Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-13032) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Uninitialized Use in GPU in Microsoft Edge vulnerability
Uninitialized Use in GPU in Microsoft Edge vulnerability (CVE-2026-13030) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in WebGL in Microsoft Edge vulnerability
Use after free in WebGL in Microsoft Edge vulnerability (CVE-2026-13028) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Windows Common Log File System Driver Elevation of Privilege vulnerability
Windows Common Log File System Driver Elevation of Privilege vulnerability (CVE-2026-50697) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Install Service Elevation of Privilege vulnerability
Microsoft Install Service Elevation of Privilege vulnerability (CVE-2026-50343) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Out of bounds write in Codecs in Microsoft Edge vulnerability
Out of bounds write in Codecs in Microsoft Edge vulnerability (CVE-2026-16807) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in WebMCP in Microsoft Edge vulnerability
Use after free in WebMCP in Microsoft Edge vulnerability (CVE-2026-16806) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Blink in Microsoft Edge vulnerability
Use after free in Blink in Microsoft Edge vulnerability (CVE-2026-16805) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Input in Microsoft Edge vulnerability
Use after free in Input in Microsoft Edge vulnerability (CVE-2026-16804) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.
Azure Portal Information Disclosure vulnerability
Azure Portal Information Disclosure vulnerability (CVE-2026-62835) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Edge Copilot Remote Code Execution vulnerability
Microsoft Edge Copilot Remote Code Execution vulnerability (CVE-2026-48561) was added to Microsoft’s security update guidance. Corrected the CVE description and title. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Azure Key Vault Elevation of Privilege vulnerability
Azure Key Vault Elevation of Privilege vulnerability (CVE-2026-62825) was added to Microsoft’s security update guidance. Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability
Azure App Service on Azure Stack Hub Elevation of Privilege vulnerability (CVE-2026-58630) was added to Microsoft’s security update guidance. Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.