Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-55029

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55029) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55028

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55028) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55027

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55027) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55026

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55026) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55025

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55025) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55024

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55024) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55023

Microsoft Office Information Disclosure vulnerability

Microsoft Office Information Disclosure vulnerability (CVE-2026-55023) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55022

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55022) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55021

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55021) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55020

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55020) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55019

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55019) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55018

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55018) was added to Microsoft’s security update guidance. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55017

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55017) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55016

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-55016) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55014

Windows Remote Help Defense Elevation of Privilege vulnerability

Windows Remote Help Defense Elevation of Privilege vulnerability (CVE-2026-55014) was added to Microsoft’s security update guidance. Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55012

Microsoft Defender Remote Code Execution vulnerability

Microsoft Defender Remote Code Execution vulnerability (CVE-2026-55012) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55011

Microsoft Defender Remote Code Execution vulnerability

Microsoft Defender Remote Code Execution vulnerability (CVE-2026-55011) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55009

Microsoft Exchange Server Elevation of Privilege vulnerability

Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-55009) was added to Microsoft’s security update guidance. Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55008

Microsoft Exchange Server Spoofing vulnerability

Microsoft Exchange Server Spoofing vulnerability (CVE-2026-55008) was added to Microsoft’s security update guidance. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55006

Microsoft Exchange Server Elevation of Privilege vulnerability

Microsoft Exchange Server Elevation of Privilege vulnerability (CVE-2026-55006) was added to Microsoft’s security update guidance. Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55005

Microsoft Exchange Server Remote Code Execution vulnerability

Microsoft Exchange Server Remote Code Execution vulnerability (CVE-2026-55005) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55004

Windows Print Configuration Elevation of Privilege vulnerability

Windows Print Configuration Elevation of Privilege vulnerability (CVE-2026-55004) was added to Microsoft’s security update guidance. Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55003

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-55003) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55002

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-55002) was added to Microsoft’s security update guidance. External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.