Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 20 min 42 sec ago

CVE-2026-19138 Heap buffer overflow in CrashReporting

Wed, 08/12/2026 - 00:01
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-19137 Use after free in WebGL

Wed, 08/12/2026 - 00:01
This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability

Tue, 08/11/2026 - 14:00
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Categories: Microsoft

CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability

Tue, 08/11/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 08/11/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability

Tue, 08/11/2026 - 14:00
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability

Tue, 08/11/2026 - 14:00
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability

Tue, 08/11/2026 - 14:00
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
Categories: Microsoft

CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability

Tue, 08/11/2026 - 14:00
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability

Tue, 08/11/2026 - 14:00
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability

Tue, 08/11/2026 - 14:00
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
Categories: Microsoft

CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
Categories: Microsoft

CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-58612 PowerShell Information Disclosure Vulnerability

Tue, 08/11/2026 - 14:00
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability

Tue, 08/11/2026 - 14:00
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

Pages