Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 27 min 30 sec ago

CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

Categories: Microsoft

CVE-2026-68887 Windows Message Queuing Queue Manager Denial of Service Vulnerability

9 hours 22 min ago

Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-69293 Windows Biometric Service Elevation of Privilege Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69355 Microsoft Exchange Server Remote Code Execution Vulnerability

9 hours 22 min ago

External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability

9 hours 22 min ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Categories: Microsoft

CVE-2026-69361 Microsoft Exchange Server Spoofing Vulnerability

9 hours 22 min ago
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-69375 Microsoft Exchange Server Tampering Vulnerability

9 hours 22 min ago

Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Categories: Microsoft

CVE-2026-69378 Microsoft Exchange Server Denial of Service Vulnerability

9 hours 22 min ago

Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-69380 Microsoft Exchange Server Elevation of Privilege Vulnerability

9 hours 22 min ago

Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69382 Microsoft Exchange Server Information Disclosure Vulnerability

9 hours 22 min ago

Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-69383 Windows Shell Elevation of Privilege Vulnerability

9 hours 22 min ago

External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69394 Windows Audio Service Elevation of Privilege Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69443 Windows Device Health Attestation (DHA) Information Disclosure Vulnerability

9 hours 22 min ago

Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-69469 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability

9 hours 22 min ago

Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.

Categories: Microsoft

CVE-2026-69501 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

9 hours 22 min ago

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69518 Windows Remote Desktop Remote Code Execution Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-69544 Windows SMB Client Elevation of Privilege Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-69548 Windows RNDIS Information Disclosure Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.

Categories: Microsoft

CVE-2026-69556 Microsoft Office Word Remote Code Execution Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-69583 Windows Biometric Service Elevation of Privilege Vulnerability

9 hours 22 min ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

Pages