Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 1 hour 32 sec ago

CVE-2026-52935 xfrm: espintcp: do not reuse an in-progress partial send

Fri, 07/03/2026 - 08:02
Information published.
Categories: Microsoft

CVE-2026-53130 fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START

Fri, 07/03/2026 - 08:02
Information published.
Categories: Microsoft

CVE-2026-53357 Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()

Fri, 07/03/2026 - 08:02
Information published.
Categories: Microsoft

CVE-2026-53048 gfs2: prevent NULL pointer dereference during unmount

Fri, 07/03/2026 - 08:02
Information published.
Categories: Microsoft

CVE-2026-52992 fs/adfs: validate nzones in adfs_validate_bblk()

Fri, 07/03/2026 - 08:01
Information published.
Categories: Microsoft

CVE-2026-50521 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Thu, 07/02/2026 - 14:00
Added Edge software to the Security Updates table. Customers that are running supported version of Edge are encouraged to update to the indicated version to be protected from this vulnerability.
Categories: Microsoft

CVE-2026-57100 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Thu, 07/02/2026 - 14:00
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability

Thu, 07/02/2026 - 14:00
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-26145 Microsoft Azure Synapse Elevation of Privilege Vulnerability

Thu, 07/02/2026 - 14:00
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-41106 Microsoft 365 Copilot Elevation of Privilege Vulnerability

Thu, 07/02/2026 - 14:00
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-54998 Microsoft Exchange Online Elevation of Privilege Vulnerability

Thu, 07/02/2026 - 14:00
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-7531 Use-after-free in PQC hybrid key-share handling

Wed, 07/01/2026 - 08:06
Information published.
Categories: Microsoft

CVE-2026-6412 Continued acceptance of SHA-1/MD5 digests in certificate processing

Wed, 07/01/2026 - 08:06
Information published.
Categories: Microsoft

Pages