Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 26 min 20 sec ago

CVE-2026-77890 Windows DHCP Server Denial of Service Vulnerability

9 hours 21 min ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-77889 Windows DHCP Server Denial of Service Vulnerability

9 hours 21 min ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-77891 Windows DHCP Server Remote Code Execution Vulnerability

9 hours 21 min ago

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

Categories: Microsoft

CVE-2026-77892 Windows Boot Manager Elevation of Privilege Vulnerability

9 hours 21 min ago

No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.

Categories: Microsoft

CVE-2026-77893 Windows DHCP Server Denial of Service Vulnerability

9 hours 21 min ago

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-77894 Windows Installer Elevation of Privilege Vulnerability

9 hours 21 min ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-77895 Windows DHCP Server Denial of Service Vulnerability

9 hours 21 min ago

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-77896 Windows Remote Desktop Client Denial of Service Vulnerability

9 hours 21 min ago

Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.

Categories: Microsoft

CVE-2026-69268 Microsoft Office SharePoint Remote Code Execution Vulnerability

9 hours 21 min ago

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-69285 Microsoft Office Remote Code Execution Vulnerability

9 hours 21 min ago

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-69273 Microsoft Office SharePoint Remote Code Execution Vulnerability

9 hours 21 min ago

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-69282 Microsoft Office SharePoint Remote Code Execution Vulnerability

9 hours 21 min ago

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-77898 Microsoft Office Remote Code Execution Vulnerability

9 hours 21 min ago

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-77899 Windows Security Center Elevation of Privilege Vulnerability

9 hours 21 min ago

Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-77904 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability

9 hours 21 min ago

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

Categories: Microsoft

CVE-2026-77907 Visual Studio Remote Code Execution Vulnerability

9 hours 21 min ago

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-77908 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

9 hours 21 min ago

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-77909 Azure CycleCloud Information Disclosure Vulnerability

9 hours 21 min ago

Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-78439 Microsoft Office Graphics Component Remote Code Execution Vulnerability

9 hours 21 min ago

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-78461 Visual Studio Code Security Feature Bypass Vulnerability

9 hours 21 min ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Categories: Microsoft

Pages