Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-55944

Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution vulnerability

Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution vulnerability (CVE-2026-55944) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55899

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55899) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55898

Microsoft Excel Information Disclosure vulnerability

Microsoft Excel Information Disclosure vulnerability (CVE-2026-55898) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55145

Outlook Copilot Tampering vulnerability

Outlook Copilot Tampering vulnerability (CVE-2026-55145) was added to Microsoft’s security update guidance. Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55144

Windows Cryptography API: Next Generation (CNG) Tampering vulnerability

Windows Cryptography API: Next Generation (CNG) Tampering vulnerability (CVE-2026-55144) was added to Microsoft’s security update guidance. Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55142

Microsoft Word Information Disclosure vulnerability

Microsoft Word Information Disclosure vulnerability (CVE-2026-55142) was added to Microsoft’s security update guidance. Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55141

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55141) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55140

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55140) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55139

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55139) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55138

Microsoft Excel Information Disclosure vulnerability

Microsoft Excel Information Disclosure vulnerability (CVE-2026-55138) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55136

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55136) was added to Microsoft’s security update guidance. Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55135

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55135) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55133

Microsoft OneNote Remote Code Execution vulnerability

Microsoft OneNote Remote Code Execution vulnerability (CVE-2026-55133) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55132

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-55132) was added to Microsoft’s security update guidance. Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55131

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55131) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55130

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-55130) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55128

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-55128) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55127

Microsoft Word Remote Code Execution vulnerability

Microsoft Word Remote Code Execution vulnerability (CVE-2026-55127) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55126

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55126) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55125

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55125) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55124

Microsoft Word Information Disclosure vulnerability

Microsoft Word Information Disclosure vulnerability (CVE-2026-55124) was added to Microsoft’s security update guidance. Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55122

Microsoft Excel Information Disclosure vulnerability

Microsoft Excel Information Disclosure vulnerability (CVE-2026-55122) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55120

Microsoft PowerPoint Remote Code Execution vulnerability

Microsoft PowerPoint Remote Code Execution vulnerability (CVE-2026-55120) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55058

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55058) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.