Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 1 hour 1 sec ago

CVE-2026-42895 Microsoft Copilot Tampering Vulnerability

Thu, 06/18/2026 - 14:00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
Categories: Microsoft

CVE-2026-54130 M365 Copilot Information Disclosure Vulnerability

Thu, 06/18/2026 - 14:00
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability

Thu, 06/18/2026 - 14:00
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-48584 Microsoft Azure Synapse Elevation of Privilege Vulnerability

Thu, 06/18/2026 - 14:00
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-48582 Microsoft Exchange Online Elevation of Privilege Vulnerability

Thu, 06/18/2026 - 14:00
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-47645 Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability

Thu, 06/18/2026 - 14:00
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-47646 Dynamics 365 Customer Voice Spoofing Vulnerability

Thu, 06/18/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-28387 Potential Use-after-free in DANE Client Code

Thu, 06/18/2026 - 08:50
Information published.
Categories: Microsoft

CVE-2025-71072 shmem: fix recovery on rename failures

Thu, 06/18/2026 - 08:48
Information published.
Categories: Microsoft

CVE-2025-71073 Input: lkkbd - disable pending work before freeing device

Thu, 06/18/2026 - 08:48
Information published.
Categories: Microsoft

CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability

Tue, 06/16/2026 - 14:00
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
Categories: Microsoft

Chromium: CVE-2026-11700 Use after free in Tracing

Tue, 06/16/2026 - 02:15
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-11699 Use after free in Bluetooth

Tue, 06/16/2026 - 02:15
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-11698 Use after free in Bluetooth

Tue, 06/16/2026 - 02:15
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-11697 Insufficient validation of untrusted input in UI

Tue, 06/16/2026 - 02:15
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-11696 Uninitialized Use in Video

Tue, 06/16/2026 - 02:15
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-11695 Inappropriate implementation in Passwords

Tue, 06/16/2026 - 02:15
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Pages