Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 19 min 14 sec ago

Chromium: CVE-2026-84331 Incorrect authorization in Actor

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84329 Confused deputy in CredentialProvider

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84328 Missing authorization in FileSystem

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84327 Incorrect authorization in Autofill

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84326 Uninitialized resource in V8

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84325 Improper input validation in DataTransfer

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84324 Use after free in Proxy

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-84323 Missing authorization in FileSystem

Thu, 09/03/2026 - 23:58
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

CVE-2026-62906 Microsoft Discovery Studio Information Disclosure Vulnerability

Thu, 09/03/2026 - 14:00

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-70178 Microsoft Fabric Elevation of Privilege Vulnerability

Thu, 09/03/2026 - 14:00

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability

Thu, 09/03/2026 - 14:00

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability

Thu, 09/03/2026 - 14:00

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability

Thu, 09/03/2026 - 14:00

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability

Thu, 09/03/2026 - 14:00

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

Categories: Microsoft

CVE-2026-65818 Power Automate Elevation of Privilege Vulnerability

Thu, 09/03/2026 - 14:00

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability

Thu, 09/03/2026 - 14:00

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

Mon, 08/31/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability

Fri, 08/28/2026 - 14:00

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Categories: Microsoft

CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Fri, 08/28/2026 - 14:00

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Fri, 08/28/2026 - 14:00

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

Pages