Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-58279

Azure CycleCloud Elevation of Privilege vulnerability

Azure CycleCloud Elevation of Privilege vulnerability (CVE-2026-58279) was added to Microsoft’s security update guidance. Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-58277

Microsoft SharePoint Elevation of Privilege vulnerability

Microsoft SharePoint Elevation of Privilege vulnerability (CVE-2026-58277) was added to Microsoft’s security update guidance. Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57982

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-57982) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57979

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-57979) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57976

Windows Active Directory Domain Services Denial of Service vulnerability

Windows Active Directory Domain Services Denial of Service vulnerability (CVE-2026-57976) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57973

Windows Subsystem for Linux (WSL2) Kernel Tampering vulnerability

Windows Subsystem for Linux (WSL2) Kernel Tampering vulnerability (CVE-2026-57973) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57969

Azure CycleCloud Elevation of Privilege vulnerability

Azure CycleCloud Elevation of Privilege vulnerability (CVE-2026-57969) was added to Microsoft’s security update guidance. Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57968

Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege vulnerability

Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege vulnerability (CVE-2026-57968) was added to Microsoft’s security update guidance. Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57107

Windows Admin Center Elevation of Privilege vulnerability

Windows Admin Center Elevation of Privilege vulnerability (CVE-2026-57107) was added to Microsoft’s security update guidance. Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57102

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-57102) was added to Microsoft’s security update guidance. Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57101

Visual Studio Code Security Feature Bypass vulnerability

Visual Studio Code Security Feature Bypass vulnerability (CVE-2026-57101) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57097

Microsoft XML Security Feature Bypass vulnerability

Microsoft XML Security Feature Bypass vulnerability (CVE-2026-57097) was added to Microsoft’s security update guidance. Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57096

Windows Routing and Remote Access Service (RRAS) Elevation of Privilege vulnerability

Windows Routing and Remote Access Service (RRAS) Elevation of Privilege vulnerability (CVE-2026-57096) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57094

Microsoft Windows Media Foundation Remote Code Execution vulnerability

Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-57094) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57093

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability

Windows Ancillary Function Driver for WinSock Elevation of Privilege vulnerability (CVE-2026-57093) was added to Microsoft’s security update guidance. Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57092

Microsoft Windows VMSwitch Elevation of Privilege vulnerability

Microsoft Windows VMSwitch Elevation of Privilege vulnerability (CVE-2026-57092) was added to Microsoft’s security update guidance. Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57090

Microsoft Windows Media Foundation Remote Code Execution vulnerability

Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-57090) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57089

Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution vulnerability

Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution vulnerability (CVE-2026-57089) was added to Microsoft’s security update guidance. Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57087

Microsoft Windows Media Foundation Remote Code Execution vulnerability

Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-57087) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57084

Windows File Explorer Information Disclosure vulnerability

Windows File Explorer Information Disclosure vulnerability (CVE-2026-57084) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-57083

Windows Media Photo Codec Information Disclosure vulnerability

Windows Media Photo Codec Information Disclosure vulnerability (CVE-2026-57083) was added to Microsoft’s security update guidance. Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56650

Windows Network File System Elevation of Privilege vulnerability

Windows Network File System Elevation of Privilege vulnerability (CVE-2026-56650) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56649

Windows Network File System Remote Code Execution vulnerability

Windows Network File System Remote Code Execution vulnerability (CVE-2026-56649) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-56648

Windows NFS Server Elevation of Privilege vulnerability

Windows NFS Server Elevation of Privilege vulnerability (CVE-2026-56648) was added to Microsoft’s security update guidance. Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network. If you need help checking exposure, call (864) 335-9223.