Microsoft security briefs
3324 published alerts for Microsoft products and services.
Use after free in Aura in Microsoft Edge vulnerability
Use after free in Aura in Microsoft Edge vulnerability (CVE-2026-15905) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Ozone in Microsoft Edge vulnerability
Use after free in Ozone in Microsoft Edge vulnerability (CVE-2026-15904) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Out of bounds read and write in V8 in Microsoft Edge vulnerability
Out of bounds read and write in V8 in Microsoft Edge vulnerability (CVE-2026-15903) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Cast in Microsoft Edge vulnerability
Use after free in Cast in Microsoft Edge vulnerability (CVE-2026-15902) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in Network in Microsoft Edge vulnerability
Use after free in Network in Microsoft Edge vulnerability (CVE-2026-15901) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in GPU in Microsoft Edge vulnerability
Use after free in GPU in Microsoft Edge vulnerability (CVE-2026-15900) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Use after free in CameraCapture in Microsoft Edge vulnerability
Use after free in CameraCapture in Microsoft Edge vulnerability (CVE-2026-15899) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. If you need help checking exposure, call (864) 335-9223.
Windows Backup Service Elevation of Privilege vulnerability
Windows Backup Service Elevation of Privilege vulnerability (CVE-2026-58598) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-56171) was added to Microsoft’s security update guidance. Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Remote Code Execution vulnerability
Microsoft SharePoint Remote Code Execution vulnerability (CVE-2026-58644) was added to Microsoft’s security update guidance. Corrected the Exploitability Index, Exploited flag and CVSS vector which was incorrect at the time of publication on 7/14/2026. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows NTFS Elevation of Privilege vulnerability
Windows NTFS Elevation of Privilege vulnerability (CVE-2026-56182) was added to Microsoft’s security update guidance. Updated acknowledgment. This is an informational change only. If you need help checking exposure, call (864) 335-9223.
Windows Boot Loader Security Feature Bypass vulnerability
Windows Boot Loader Security Feature Bypass vulnerability (CVE-2026-58638) was added to Microsoft’s security update guidance. Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows Client-Side Caching Elevation of Privilege vulnerability
Windows Client-Side Caching Elevation of Privilege vulnerability (CVE-2026-58637) was added to Microsoft’s security update guidance. Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft PC Manager Elevation of Privilege vulnerability
Microsoft PC Manager Elevation of Privilege vulnerability (CVE-2026-58636) was added to Microsoft’s security update guidance. Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Narrator Braille Elevation of Privilege vulnerability
Windows Narrator Braille Elevation of Privilege vulnerability (CVE-2026-58635) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Win32 Kernel Subsystem Elevation of Privilege vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege vulnerability (CVE-2026-58632) was added to Microsoft’s security update guidance. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Admin Center (WAC) Remote Code Execution vulnerability
Windows Admin Center (WAC) Remote Code Execution vulnerability (CVE-2026-58631) was added to Microsoft’s security update guidance. Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Wireless Network Manager Elevation of Privilege vulnerability
Windows Wireless Network Manager Elevation of Privilege vulnerability (CVE-2026-58628) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows DHCP Server Denial of Service vulnerability
Windows DHCP Server Denial of Service vulnerability (CVE-2026-58627) was added to Microsoft’s security update guidance. Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Services Remote Code Execution vulnerability
Windows Remote Desktop Services Remote Code Execution vulnerability (CVE-2026-58626) was added to Microsoft’s security update guidance. Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Sensor Data Service Elevation of Privilege vulnerability
Windows Sensor Data Service Elevation of Privilege vulnerability (CVE-2026-58619) was added to Microsoft’s security update guidance. Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-58618) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Security Feature Bypass vulnerability
Windows Kernel Security Feature Bypass vulnerability (CVE-2026-58614) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-58613) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.