Microsoft security briefs
3324 published alerts for Microsoft products and services.
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution vulnerability
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution vulnerability (CVE-2026-55944) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55899) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Information Disclosure vulnerability
Microsoft Excel Information Disclosure vulnerability (CVE-2026-55898) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Outlook Copilot Tampering vulnerability
Outlook Copilot Tampering vulnerability (CVE-2026-55145) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.
Windows Cryptography API: Next Generation (CNG) Tampering vulnerability
Windows Cryptography API: Next Generation (CNG) Tampering vulnerability (CVE-2026-55144) was added to Microsoft’s security update guidance. Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Information Disclosure vulnerability
Microsoft Word Information Disclosure vulnerability (CVE-2026-55142) was added to Microsoft’s security update guidance. Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55141) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-55140) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-55139) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Information Disclosure vulnerability
Microsoft Excel Information Disclosure vulnerability (CVE-2026-55138) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55136) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55135) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft OneNote Remote Code Execution vulnerability
Microsoft OneNote Remote Code Execution vulnerability (CVE-2026-55133) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-55132) was added to Microsoft’s security update guidance. Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55131) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-55130) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-55128) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Remote Code Execution vulnerability
Microsoft Word Remote Code Execution vulnerability (CVE-2026-55127) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55126) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-55125) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Word Information Disclosure vulnerability
Microsoft Word Information Disclosure vulnerability (CVE-2026-55124) was added to Microsoft’s security update guidance. Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Information Disclosure vulnerability
Microsoft Excel Information Disclosure vulnerability (CVE-2026-55122) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft PowerPoint Remote Code Execution vulnerability
Microsoft PowerPoint Remote Code Execution vulnerability (CVE-2026-55120) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55058) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.