Microsoft security briefs
3324 published alerts for Microsoft products and services.
Microsoft Windows Media Foundation Remote Code Execution vulnerability
Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-58610) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Graphics Component Remote Code Execution vulnerability
Windows Graphics Component Remote Code Execution vulnerability (CVE-2026-58609) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Print Spooler Remote Code Execution vulnerability
Windows Print Spooler Remote Code Execution vulnerability (CVE-2026-58608) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kernel-Mode Driver Elevation of Privilege vulnerability
Windows Kernel-Mode Driver Elevation of Privilege vulnerability (CVE-2026-58602) was added to Microsoft’s security update guidance. Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Bing App for IOS Spoofing vulnerability
Microsoft Bing App for IOS Spoofing vulnerability (CVE-2026-58595) was added to Microsoft’s security update guidance. Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58546) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Security Feature Bypass vulnerability
Windows Kernel Security Feature Bypass vulnerability (CVE-2026-58545) was added to Microsoft’s security update guidance. Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.
Windows Management Services Elevation of Privilege vulnerability
Windows Management Services Elevation of Privilege vulnerability (CVE-2026-58544) was added to Microsoft’s security update guidance. Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Media Remote Code Execution vulnerability
Windows Media Remote Code Execution vulnerability (CVE-2026-58542) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft DWM Core Library Elevation of Privilege vulnerability
Microsoft DWM Core Library Elevation of Privilege vulnerability (CVE-2026-58541) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Installer Elevation of Privilege vulnerability
Windows Installer Elevation of Privilege vulnerability (CVE-2026-58540) was added to Microsoft’s security update guidance. Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58539) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege vulnerability
Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege vulnerability (CVE-2026-58537) was added to Microsoft’s security update guidance. Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege vulnerability (CVE-2026-58536) was added to Microsoft’s security update guidance. Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58535) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Input Method Editor (IME) Elevation of Privilege vulnerability
Windows Input Method Editor (IME) Elevation of Privilege vulnerability (CVE-2026-58534) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Client Information Disclosure vulnerability
Windows Remote Desktop Client Information Disclosure vulnerability (CVE-2026-58533) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows Kernel Elevation of Privilege vulnerability
Windows Kernel Elevation of Privilege vulnerability (CVE-2026-58532) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows SMB Elevation of Privilege vulnerability
Windows SMB Elevation of Privilege vulnerability (CVE-2026-58531) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.
Windows Resilient File System (ReFS) Remote Code Execution vulnerability
Windows Resilient File System (ReFS) Remote Code Execution vulnerability (CVE-2026-58530) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability
Windows Active Directory Federation Services (ADFS) Information Disclosure vulnerability (CVE-2026-58529) was added to Microsoft’s security update guidance. Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Windows USB Audio Class Driver Information Disclosure vulnerability
Windows USB Audio Class Driver Information Disclosure vulnerability (CVE-2026-58528) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. If you need help checking exposure, call (864) 335-9223.
Windows Runtime Elevation of Privilege vulnerability
Windows Runtime Elevation of Privilege vulnerability (CVE-2026-58527) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Storage Elevation of Privilege vulnerability
Windows Storage Elevation of Privilege vulnerability (CVE-2026-58526) was added to Microsoft’s security update guidance. Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.