Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-58610

Microsoft Windows Media Foundation Remote Code Execution vulnerability

Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-58610) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58609

Windows Graphics Component Remote Code Execution vulnerability

Windows Graphics Component Remote Code Execution vulnerability (CVE-2026-58609) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58608

Windows Print Spooler Remote Code Execution vulnerability

Windows Print Spooler Remote Code Execution vulnerability (CVE-2026-58608) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58602

Windows Kernel-Mode Driver Elevation of Privilege vulnerability

Windows Kernel-Mode Driver Elevation of Privilege vulnerability (CVE-2026-58602) was added to Microsoft’s security update guidance. Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58595

Microsoft Bing App for IOS Spoofing vulnerability

Microsoft Bing App for IOS Spoofing vulnerability (CVE-2026-58595) was added to Microsoft’s security update guidance. Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58546

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58546) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58545

Windows Kernel Security Feature Bypass vulnerability

Windows Kernel Security Feature Bypass vulnerability (CVE-2026-58545) was added to Microsoft’s security update guidance. Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58544

Windows Management Services Elevation of Privilege vulnerability

Windows Management Services Elevation of Privilege vulnerability (CVE-2026-58544) was added to Microsoft’s security update guidance. Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58542

Windows Media Remote Code Execution vulnerability

Windows Media Remote Code Execution vulnerability (CVE-2026-58542) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58541

Microsoft DWM Core Library Elevation of Privilege vulnerability

Microsoft DWM Core Library Elevation of Privilege vulnerability (CVE-2026-58541) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58540

Windows Installer Elevation of Privilege vulnerability

Windows Installer Elevation of Privilege vulnerability (CVE-2026-58540) was added to Microsoft’s security update guidance. Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58539

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58539) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58537

Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege vulnerability

Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege vulnerability (CVE-2026-58537) was added to Microsoft’s security update guidance. Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58536

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability

Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-58536) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58535

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58535) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58534

Windows Input Method Editor (IME) Elevation of Privilege vulnerability

Windows Input Method Editor (IME) Elevation of Privilege vulnerability (CVE-2026-58534) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58533

Windows Remote Desktop Client Information Disclosure vulnerability

Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58533) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58532

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-58532) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58531

Windows SMB Elevation of Privilege vulnerability

Windows SMB Elevation of Privilege vulnerability (CVE-2026-58531) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58530

Windows Resilient File System (ReFS) Remote Code Execution vulnerability

Windows Resilient File System (ReFS) Remote Code Execution vulnerability (CVE-2026-58530) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58529

Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability

Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability (CVE-2026-58529) was added to Microsoft’s security update guidance. Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58528

Windows USB Audio Class Driver Information Disclosure vulnerability

Windows USB Audio Class Driver Information Disclosure vulnerability (CVE-2026-58528) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58527

Windows Runtime Elevation of Privilege vulnerability

Windows Runtime Elevation of Privilege vulnerability (CVE-2026-58527) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58526

Windows Storage Elevation of Privilege vulnerability

Windows Storage Elevation of Privilege vulnerability (CVE-2026-58526) was added to Microsoft’s security update guidance. Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.