Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 47 min 49 sec ago

CVE-2026-55011 Microsoft Defender Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-55012 Microsoft Defender Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-50524 .NET Framework Denial of Service Vulnerability

Tue, 07/14/2026 - 14:00
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-55002 Microsoft SQL Server Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-55144 Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability

Tue, 07/14/2026 - 14:00
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
Categories: Microsoft

CVE-2026-50520 Visual Studio Code Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-54108 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 07/14/2026 - 14:00
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-50675 Microsoft Excel Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-50678 Microsoft Excel Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-54988 Microsoft Excel Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-55899 Microsoft Excel Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-55948 Microsoft Excel Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-56169 Windows Admin Center Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-56170 ASP.NET Core Denial of Service Vulnerability

Tue, 07/14/2026 - 14:00
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-50694 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-54127 Windows Hyper-V Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
Categories: Microsoft

Pages