Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 10 min 38 sec ago

Chromium: CVE-2026-79293 Information leak in Animation

Fri, 08/28/2026 - 14:00
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

CVE-2026-70309 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Fri, 08/28/2026 - 14:00

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Categories: Microsoft

CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability

Thu, 08/27/2026 - 14:00
Updated CWE value. This is an informational change only.
Categories: Microsoft

CVE-2026-32202 Windows Shell Spoofing Vulnerability

Fri, 08/21/2026 - 14:00
Updated an acknowledgement. This is an informational change only.
Categories: Microsoft

CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability

Thu, 08/20/2026 - 14:00

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability

Thu, 08/20/2026 - 14:00

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability

Thu, 08/20/2026 - 14:00

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

Categories: Microsoft

CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability

Thu, 08/20/2026 - 14:00

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

Categories: Microsoft

CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability

Thu, 08/20/2026 - 14:00
Information published. This CVE was addressed by updates that were released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who have already installed the August 2026 updates do not need to take any further action.
Categories: Microsoft

CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

Thu, 08/20/2026 - 14:00

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability

Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability

Thu, 08/20/2026 - 14:00

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

Categories: Microsoft

Pages