Microsoft security briefs
3324 published alerts for Microsoft products and services.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55029) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-55028) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-55027) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-55026) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55025) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Excel Remote Code Execution vulnerability
Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55024) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Information Disclosure vulnerability
Microsoft Office Information Disclosure vulnerability (CVE-2026-55023) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-55022) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55021) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55020) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55019) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-55018) was added to Microsoft’s security update guidance. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Remote Code Execution vulnerability
Microsoft Office Remote Code Execution vulnerability (CVE-2026-55017) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Server Spoofing vulnerability
Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55016) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Windows Remote Help Defense Elevation of Privilege vulnerability
Windows Remote Help Defense Elevation of Privilege vulnerability (CVE-2026-55014) was added to Microsoft’s security update guidance. Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Remote Code Execution vulnerability
Microsoft Defender Remote Code Execution vulnerability (CVE-2026-55012) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Defender Remote Code Execution vulnerability
Microsoft Defender Remote Code Execution vulnerability (CVE-2026-55011) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Elevation of Privilege vulnerability
Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-55009) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Spoofing vulnerability
Microsoft Exchange Server Spoofing vulnerability (CVE-2026-55008) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Elevation of Privilege vulnerability
Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-55006) was added to Microsoft’s security update guidance. Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Remote Code Execution vulnerability
Microsoft Exchange Server Remote Code Execution vulnerability (CVE-2026-55005) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.
Windows Print Configuration Elevation of Privilege vulnerability
Windows Print Configuration Elevation of Privilege vulnerability (CVE-2026-55004) was added to Microsoft’s security update guidance. Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-55003) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.
Microsoft SQL Server Elevation of Privilege vulnerability
Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-55002) was added to Microsoft’s security update guidance. External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.