Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-58275

Azure DNS Elevation of Privilege vulnerability

Azure DNS Elevation of Privilege vulnerability (CVE-2026-58275) was added to Microsoft’s security update guidance. Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56191

Microsoft Exchange Online Tampering vulnerability

Microsoft Exchange Online Tampering vulnerability (CVE-2026-56191) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56167

Azure AI Search Elevation of Privilege vulnerability

Azure AI Search Elevation of Privilege vulnerability (CVE-2026-56167) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56165

Microsoft Account Remote Code Execution vulnerability

Microsoft Account Remote Code Execution vulnerability (CVE-2026-56165) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56163

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability

Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-56163) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56160

Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability

Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability (CVE-2026-56160) was added to Microsoft’s security update guidance. Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54120

Microsoft Surface Remote Code Execution vulnerability

Microsoft Surface Remote Code Execution vulnerability (CVE-2026-54120) was added to Microsoft’s security update guidance. Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50517

Microsoft M365 Copilot Remote Code Execution vulnerability

Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-50517) was added to Microsoft’s security update guidance. Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-49159

Microsoft Graph Information Disclosure vulnerability

Microsoft Graph Information Disclosure vulnerability (CVE-2026-49159) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-35425

Azure API Management (APIM) Remote Code Execution vulnerability

Azure API Management (APIM) Remote Code Execution vulnerability (CVE-2026-35425) was added to Microsoft’s security update guidance. Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-50522

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-50522). Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. CISA remediation due date: 2026-07-25. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50458

Microsoft Brokering File System Elevation of Privilege vulnerability

Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-50458) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50441

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50441) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50407

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability

Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50407) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50377

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-50377) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58640

Windows NTFS Remote Code Execution vulnerability

Windows NTFS Remote Code Execution vulnerability (CVE-2026-58640) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50653

Azure Active Directory Denial of Service vulnerability

Azure Active Directory Denial of Service vulnerability (CVE-2026-50653) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50652

Azure Active Directory Denial of Service vulnerability

Azure Active Directory Denial of Service vulnerability (CVE-2026-50652) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50411

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50411) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50368

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50368) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50355

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50355) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50324

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50324) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-50304

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50304) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2024-35248

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-35248) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.