Skip to main content

Microsoft security briefs

3324 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-55000

Windows USB Print Driver Elevation of Privilege vulnerability

Windows USB Print Driver Elevation of Privilege vulnerability (CVE-2026-55000) was added to Microsoft’s security update guidance. Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54999

Windows TCP/IP Remote Code Execution vulnerability

Windows TCP/IP Remote Code Execution vulnerability (CVE-2026-54999) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54997

Windows SMB Information Disclosure vulnerability

Windows SMB Information Disclosure vulnerability (CVE-2026-54997) was added to Microsoft’s security update guidance. Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54996

Windows USB Print Driver Elevation of Privilege vulnerability

Windows USB Print Driver Elevation of Privilege vulnerability (CVE-2026-54996) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54995

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability (CVE-2026-54995) was added to Microsoft’s security update guidance. Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54993

Microsoft Windows Media Foundation Remote Code Execution vulnerability

Microsoft Windows Media Foundation Remote Code Execution vulnerability (CVE-2026-54993) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54992

Microsoft Message Queuing Queue Manager Remote Code Execution vulnerability

Microsoft Message Queuing Queue Manager Remote Code Execution vulnerability (CVE-2026-54992) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54991

Windows USB Print Driver Elevation of Privilege vulnerability

Windows USB Print Driver Elevation of Privilege vulnerability (CVE-2026-54991) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54988

Microsoft Excel Information Disclosure vulnerability

Microsoft Excel Information Disclosure vulnerability (CVE-2026-54988) was added to Microsoft’s security update guidance. Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54987

Windows Overlay Filter Elevation of Privilege vulnerability

Windows Overlay Filter Elevation of Privilege vulnerability (CVE-2026-54987) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54986

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-54986) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54983

Windows Active Directory Federation Services Denial of Service vulnerability

Windows Active Directory Federation Services Denial of Service vulnerability (CVE-2026-54983) was added to Microsoft’s security update guidance. Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54982

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution vulnerability (CVE-2026-54982) was added to Microsoft’s security update guidance. Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54132

Windows Kernel Elevation of Privilege vulnerability

Windows Kernel Elevation of Privilege vulnerability (CVE-2026-54132) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54131

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-54131) was added to Microsoft’s security update guidance. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54129

Windows Hyper-V Elevation of Privilege vulnerability

Windows Hyper-V Elevation of Privilege vulnerability (CVE-2026-54129) was added to Microsoft’s security update guidance. Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54127

Windows Hyper-V Elevation of Privilege vulnerability

Windows Hyper-V Elevation of Privilege vulnerability (CVE-2026-54127) was added to Microsoft’s security update guidance. Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54126

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure vulnerability (CVE-2026-54126) was added to Microsoft’s security update guidance. Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54125

Windows Runtime Elevation of Privilege vulnerability

Windows Runtime Elevation of Privilege vulnerability (CVE-2026-54125) was added to Microsoft’s security update guidance. Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54122

Windows GDI+ Remote Code Execution vulnerability

Windows GDI+ Remote Code Execution vulnerability (CVE-2026-54122) was added to Microsoft’s security update guidance. Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54119

Windows Active Directory Denial of Service vulnerability

Windows Active Directory Denial of Service vulnerability (CVE-2026-54119) was added to Microsoft’s security update guidance. Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54116

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-54116) was added to Microsoft’s security update guidance. Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54115

Windows Message Queuing (MSMQ) Elevation of Privilege vulnerability

Windows Message Queuing (MSMQ) Elevation of Privilege vulnerability (CVE-2026-54115) was added to Microsoft’s security update guidance. Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-54114

Windows Win32k Elevation of Privilege vulnerability

Windows Win32k Elevation of Privilege vulnerability (CVE-2026-54114) was added to Microsoft’s security update guidance. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. If you need help checking exposure, call (864) 335-9223.