Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 32 min 14 sec ago

CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability

8 hours 26 min ago

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability

8 hours 26 min ago

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability

8 hours 26 min ago

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-66304 Skype for Business Information Disclosure Vulnerability

8 hours 26 min ago

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability

8 hours 26 min ago

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-66306 Skype for Business Information Disclosure Vulnerability

8 hours 26 min ago

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability

8 hours 26 min ago

Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability

8 hours 26 min ago

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69341 Windows Image Acquisition Elevation of Privilege Vulnerability

8 hours 26 min ago

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability

8 hours 26 min ago

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-70091 Windows DNS Denial of Service Vulnerability

8 hours 26 min ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-69782 Windows DNS Server Remote Code Execution Vulnerability

8 hours 26 min ago

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability

8 hours 26 min ago

Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-85360 Windows Kernel Elevation of Privilege Vulnerability

8 hours 26 min ago

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability

8 hours 26 min ago

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-57098 Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability

8 hours 26 min ago

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-62801 Microsoft PowerShell Security Feature Bypass Vulnerability

8 hours 26 min ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.

Categories: Microsoft

CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability

8 hours 26 min ago
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

8 hours 26 min ago
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-67368 Microsoft SQL Server Elevation of Privilege Vulnerability

8 hours 26 min ago

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

Pages