Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 55 min 30 sec ago

CVE-2026-58637 Windows Client-Side Caching Elevation of Privilege Vulnerability

Tue, 07/14/2026 - 14:00
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-58638 Windows Boot Loader Security Feature Bypass Vulnerability

Tue, 07/14/2026 - 14:00
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-56181 Windows Network Address Translation (NAT) Spoofing Vulnerability

Tue, 07/14/2026 - 14:00
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Categories: Microsoft

CVE-2026-55121 Microsoft Office Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Categories: Microsoft

CVE-2026-58529 Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability

Tue, 07/14/2026 - 14:00
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-55008 Microsoft Exchange Server Spoofing Vulnerability

Tue, 07/14/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-40467 Use after free in gawk

Tue, 07/14/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-40468 Heap buffer overflow in gawk

Tue, 07/14/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-40469 Heap buffer overflow in gawk

Tue, 07/14/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-40553 Stack-based buffer overflow in gawk

Tue, 07/14/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input

Sun, 07/12/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion

Sun, 07/12/2026 - 08:01
Information published.
Categories: Microsoft

Chromium: CVE-2026-14428 Insufficient validation of untrusted input in Dawn

Sat, 07/11/2026 - 22:41
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE

Sat, 07/11/2026 - 22:41
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-14126 Incorrect security UI in UI

Sat, 07/11/2026 - 22:41
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-14114 Inappropriate implementation in WebAppInstalls

Sat, 07/11/2026 - 22:41
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-14096 Object lifecycle issue in Input

Sat, 07/11/2026 - 22:41
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-14005 Use after free in Omnibox

Sat, 07/11/2026 - 22:41
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Pages