Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 47 min 36 sec ago

CVE-2026-12445 Use after free in Extensions

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-12443 Use after free in Web Authentication

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-12441 Use after free in File Input

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-12440 Use after free in DigitalCredentials

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-12439 Use after free in Digital Credentials

Fri, 06/19/2026 - 20:52
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-24289 Windows Kernel Elevation of Privilege Vulnerability

Fri, 06/19/2026 - 14:00
Acknowledgement added. This is an informational change only.
Categories: Microsoft

CVE-2025-6965 Integer Truncation on SQLite

Fri, 06/19/2026 - 14:00
Added Visual Studio software to the Security Updates table. Customers that are running supported version of Visual Studio are encouraged to update to the indicated version to be protected from this vulnerability.
Categories: Microsoft

CVE-2026-48914 Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling

Fri, 06/19/2026 - 08:43
Information published.
Categories: Microsoft

CVE-2026-12087 Socket versions before 2.041 for Perl have an out-of-bounds heap read

Fri, 06/19/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-53689

Fri, 06/19/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-42014 Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin

Fri, 06/19/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-44967 opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response

Fri, 06/19/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-47633 Microsoft Cost Management Information Disclosure Vulnerability

Thu, 06/18/2026 - 14:00
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-32208 Microsoft Edge (Chromium-based) Spoofing Vulnerability

Thu, 06/18/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-32174 Azure Bot Service Elevation of Privilege Vulnerability

Thu, 06/18/2026 - 14:00
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability

Thu, 06/18/2026 - 14:00
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

Pages