Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 29 min 34 sec ago

CVE-2026-47652 Windows Hyper-V Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-47654 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-48563 Remote Desktop Client Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-48566 Windows DWM Core Library Information Disclosure Vulnerability

Tue, 06/09/2026 - 14:00
Information published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to take any further action.
Categories: Microsoft

CVE-2026-48568 Secure Boot Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-48570 Secure Boot Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-48573 Secure Boot Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-48575 Secure Boot Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-48576 Secure Boot Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-48578 Secure Boot Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-48583 Windows Kernel Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

ADV990001 Latest Servicing Stack Updates

Tue, 06/09/2026 - 14:00
Advisory updated to announce new versions of Servicing Stack Updates are available. Please see the FAQ for details.
Categories: Microsoft

CVE-2026-49161 Microsoft PC Manager Security Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-50508 Windows NTLM Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-26142 Nuance PowerScribe Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

Chromium: CVE-2026-11148 Inappropriate implementation in Payments

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

CVE-2026-33113 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-42828 Windows Projected File System Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-42829 Windows Administrator Protection Secure Feature Bypass Vulnerability

Tue, 06/09/2026 - 14:00
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

Pages