Feed aggregator

Chromium: CVE-2026-79291 Information leak in CSS

Microsoft Security Center Center News - Fri, 08/28/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-79292 Integer overflow in Chromecast

Microsoft Security Center Center News - Fri, 08/28/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-79293 Information leak in Animation

Microsoft Security Center Center News - Fri, 08/28/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

CVE-2026-70309 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Microsoft Security Center Center News - Fri, 08/28/2026 - 14:00

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Categories: Microsoft

CVE-2026-42993 Remote Desktop Client Remote Code Execution Vulnerability

Microsoft Security Center Center News - Thu, 08/27/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability

Microsoft Security Center Center News - Thu, 08/27/2026 - 14:00
Updated CWE value. This is an informational change only.
Categories: Microsoft

CVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability

Microsoft Security Center Center News - Mon, 08/24/2026 - 14:00
Affected software updated with new package information.
Categories: Microsoft

CVE-2026-32202 Windows Shell Spoofing Vulnerability

Microsoft Security Center Center News - Fri, 08/21/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

New - Citrix Infra Monitor

New downloads are available for Citrix Virtual Apps and Desktops
Categories: Citrix

CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

Categories: Microsoft

CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

Categories: Microsoft

CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00
Information published. This CVE was addressed by updates that were released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who have already installed the August 2026 updates do not need to take any further action.
Categories: Microsoft

CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

Microsoft Security Center Center News - Thu, 08/20/2026 - 14:00

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

Pages

Subscribe to Geeksultant aggregator