Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 9 min 19 sec ago

Chromium: CVE-2026-10953 Use after free in Core

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11007 Insufficient validation of untrusted input in WebView

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11163 Use after free in Messages

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11108 Inappropriate implementation in NFC

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11215 Inappropriate implementation in Cronet

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11270 Inappropriate implementation in UI

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-10892 Out of bounds write in GPU

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11263 Insufficient policy enforcement in WebAuthentication

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11045 Insufficient validation of untrusted input in GPU

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-11097 Inappropriate implementation in WebView

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

Chromium: CVE-2026-10883 Out of bounds write in ANGLE

Tue, 06/09/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Categories: Microsoft

CVE-2026-41108 Windows DNS Client Elevation of Privilege Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-45467 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-45468 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-45469 Microsoft Excel Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45475 Microsoft Office Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45472 Microsoft Office Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45471 Microsoft Word Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45474 Microsoft Office Remote Code Execution Vulnerability

Tue, 06/09/2026 - 14:00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-45479 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 06/09/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

Pages