Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 35 min 2 sec ago

CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows

Wed, 07/15/2026 - 08:03
Information published.
Categories: Microsoft

CVE-2026-42505 Invoking Encrypted Client Hello privacy leak in crypto/tls

Wed, 07/15/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-39822 Root escape via symlink plus trailing slash in os

Wed, 07/15/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-48561 Microsoft Copilot Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-42982 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-47296 Microsoft SQL Server Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-34349 Windows Media Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-34346 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-42900 Microsoft Windows App Store Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

Pages