Microsoft security briefs
3324 published alerts for Microsoft products and services.
Azure DNS Elevation of Privilege vulnerability
Azure DNS Elevation of Privilege vulnerability (CVE-2026-58275) was added to Microsoft’s security update guidance. Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Online Tampering vulnerability
Microsoft Exchange Online Tampering vulnerability (CVE-2026-56191) was added to Microsoft’s security update guidance. Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.
Azure AI Search Elevation of Privilege vulnerability
Azure AI Search Elevation of Privilege vulnerability (CVE-2026-56167) was added to Microsoft’s security update guidance. Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Account Remote Code Execution vulnerability
Microsoft Account Remote Code Execution vulnerability (CVE-2026-56165) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability
Microsoft Azure Kubernetes Service Elevation of Privilege vulnerability (CVE-2026-56163) was added to Microsoft’s security update guidance. Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability
Azure Red Hat OpenShift (ARO) Elevation of Privilege vulnerability (CVE-2026-56160) was added to Microsoft’s security update guidance. Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Surface Remote Code Execution vulnerability
Microsoft Surface Remote Code Execution vulnerability (CVE-2026-54120) was added to Microsoft’s security update guidance. Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft M365 Copilot Remote Code Execution vulnerability
Microsoft M365 Copilot Remote Code Execution vulnerability (CVE-2026-50517) was added to Microsoft’s security update guidance. Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Graph Information Disclosure vulnerability
Microsoft Graph Information Disclosure vulnerability (CVE-2026-49159) was added to Microsoft’s security update guidance. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Azure API Management (APIM) Remote Code Execution vulnerability
Azure API Management (APIM) Remote Code Execution vulnerability (CVE-2026-35425) was added to Microsoft’s security update guidance. Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-50522). Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. CISA remediation due date: 2026-07-25. If you need help checking exposure, call (864) 335-9223.
Microsoft Brokering File System Elevation of Privilege vulnerability
Microsoft Brokering File System Elevation of Privilege vulnerability (CVE-2026-50458) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50441) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability
Windows Resilient File System (ReFS) Elevation of Privilege vulnerability (CVE-2026-50407) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-50377) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Remote Code Execution vulnerability
Windows NTFS Remote Code Execution vulnerability (CVE-2026-58640) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Azure Active Directory Denial of Service vulnerability
Azure Active Directory Denial of Service vulnerability (CVE-2026-50653) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Azure Active Directory Denial of Service vulnerability
Azure Active Directory Denial of Service vulnerability (CVE-2026-50652) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50411) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50368) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50355) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50324) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services Denial of Service vulnerability
Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-50304) was added to Microsoft’s security update guidance. Updated product information in the Software Update table. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability
Microsoft Dynamics 365 Business Central Elevation of Privilege vulnerability (CVE-2024-35248) was added to Microsoft’s security update guidance. Updated the build numbers. This is an informational update only. If you need help checking exposure, call (864) 335-9223.