Výsledky hledání

výrobce: Microsoft× v celém archivu zrušit filtry

1035 karet z 1072 položek · strana 1 z 18 CZ · EN/orig

1

Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-62874, CVE-2026-68791, CVE-2026-69399, CVE-2026-70009, CVE-2026-69843, CVE-2026-69865, CVE-2026-70200, CVE-2026-83944, CVE-2026-77903, CVE-2026-78501, CVE-2026-83946, CVE-2026-85878, CVE-2026-85885, CVE-2026-85887, CVE-2026-85889, CVE-2026-85917, CVE-2026-87701, CVE-2026-55946, Summary: Microsoft has addressed multiple vulnerabilities affecting Azure, Microsoft Fabric, Azure AI Foundry,…

CVSS 10.0 Microsoft FI

tg: zranitelnost tp: AI

· NCSC-FI · Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

4

Secure enterprise sharing with access reviews for Microsoft 365

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

Microsoft US

tg: návod tg: propagace tp: identita

· BleepingComputer · Secure enterprise sharing with access reviews for Microsoft 365

8

From guidance to action: Security fundamentals that materially reduce risk 

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how quickly these weaknesses can combine into attack paths that cross…

Microsoft US

tg: rozbor tg: návod tg: propagace tp: malware tp: phishing tp: AI tp: identita

· Microsoft Security Blog · From guidance to action: Security fundamentals that materially reduce risk 

Improving email security outcomes with real-world Microsoft Defender insights

Every benchmark tells a story. The most valuable ones tell us where to improve next. For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes. The results have shown strong Microsoft Defender performance across pre-delivery and post-delivery scenarios, while revealing where threats and defenses continue to evolve. This quarter’s benchmark examines how continuous measurement informs protection…

Microsoft US

tg: rozbor tg: propagace tp: AI

· Microsoft Security Blog · Improving email security outcomes with real-world Microsoft Defender insights

3

NightEagle targets Russian companies

Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign. Initial access In most incidents, the attackers used compromised valid…

KEV ✓ · ransomware EPSS 1.00 CVE-2019-0708 CVE-2020-0688 Microsoft RU

tg: varování tg: rozbor tp: malware tp: špionáž

· Securelist (Kaspersky) · NightEagle targets Russian companies

ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.

CVSS 5.3 Microsoft US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

5

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and security teams focus on deeper testing where needed while allowing high-confidence patches to move…

Microsoft US

tg: zranitelnost tg: návod tg: propagace tp: AI

· Qualys · Before You Patch. Why Patch Reliability Matters for Confident Deployment

4

Upozornění na Device Code Phishing

Upozorňujeme na phishingovou kampaň zneužívající autentizační mechanismus Device Code Flow. Útočník pod záminkou připojení ke schůzce nebo videohovoru přes legitimní nástroje přiměje uživatele k autorizaci a přes kontrolovanou relaci dochází ke krádeži přístupového tokenu a následné kompromitaci uživatele.Device Code FlowDevice Code Flow je autentizační mechanismus navržený pro případy, kdy se uživatel přihlašuje na zařízení s omezenými možnostmi zadávání přihlašovacích údajů, například na…

Microsoft CZ

tg: varování tg: návod tp: phishing tp: identita

· NÚKIB · Upozornění na Device Code Phishing

14th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with the…

KEV ✓ EPSS 0.94 CVSS 10.0 CVE-2026-67276 CVE-2026-72898 CVE-2026-81963 CVE-2026-85046 CVE-2026-85706 CVE-2026-85880 CVE-2026-86060 Microsoft GitLab MikroTik Anthropic IL

tg: incident tg: zranitelnost tg: přehled tp: malware tp: únik dat tp: AI

· Check Point Research · 14th September – Threat Intelligence Report

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Over 15 months and seven campaigns, they built a malicious browser extension that installs…

Google Microsoft finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

SPOJENO PŘES CVE Multiples vulnérabilités dans Microsoft Edge (14 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur. Microsoft indique que la vulnérabilité CVE-2026-87491 est activement exploitée.

KEV ✓ EPSS 0.01 CVE-2026-87491 Microsoft Google Chrome FR HR US CA NL

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Edge (14 septembre 2026) · CERT.hr · Google je izdao zakrpe za 230 ranjivosti. Ažurirajte Chrome preglednik. · Malwarebytes Labs · Update Chrome now to protect against an actively exploited vulnerability · Cyber Centre Kanada · Google security advisory (AV26-904) · NCSC-NL · NCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chrome · CISA KEV · Google Chromium V8 Out of Bounds Write Vulnerability (CVE-2026-87491)

4

6

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod tp: identita

· Microsoft Security Blog · Detect and disrupt AI-themed attacks with Microsoft Defender

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless. But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running…

Google Microsoft US

tg: varování tg: zneužíváno tg: rozbor tg: propagace tp: malware tp: phishing tp: špionáž

· Malwarebytes Labs · BlueMoon exploit kit turns Chrome and Windows flaws into attacks

SPOJENO PŘES CVE New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

KEV ✓ EPSS 0.01 CVE-2026-85046 CVE-2026-85880 CVE-2026-87491 Microsoft Google US

tg: varování tg: zneužíváno tg: rozbor tp: malware tp: phishing tp: špionáž

· BleepingComputer · New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws · Volexity · Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

SPOJENO PŘES CVE Vulnérabilité dans Microsoft Edge (10 septembre 2026)

Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-85046 est activement exploitée.

KEV ✓ EPSS 0.01 CVE-2026-85046 Microsoft Google veřejná správa FR CA NL US IT

tg: zneužíváno tg: zranitelnost tg: regulace

· CERT-FR – avis · Vulnérabilité dans Microsoft Edge (10 septembre 2026) · Cyber Centre Kanada · Google security advisory (AV26-883) · NCSC-NL · NCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chrome · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CSIRT Itálie (ACN) · Google: rilevato sfruttamento di vulnerabilità zero-day in Chrome · CISA KEV · Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046)

16

Threat Matrix: Mapping threats across cloud web applications

In this article OverviewTechnique CatalogPrivilege EscalationMitigation and protection guidanceReferencesLearn more Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. Cloud-hosted web applications and serverless platforms create attack paths that can cross application code, managed runtimes, workload identities, deployment pipelines,…

Microsoft US

tg: rozbor tg: návod

· Microsoft Security Blog · Threat Matrix: Mapping threats across cloud web applications

Passkey-themed social engineering leads to identity and cloud compromise

In this article Attack chain overviewAttributionMitigation and protection guidanceLearn more Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. Microsoft Security Research assesses that this sequence is consistent with automated collection from…

Microsoft US

tg: varování tg: rozbor tp: phishing tp: únik dat tp: identita

· Microsoft Security Blog · Passkey-themed social engineering leads to identity and cloud compromise

SPOJENO PŘES CVE Microsoft fixes record 964 flaws, including 2 exploited zero-days

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch. The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of…

KEV ✓ EPSS 0.01 CVSS 7.8 CVE-2026-81963 CVE-2026-85880 Microsoft US CA

tg: zneužíváno tg: zranitelnost tg: propagace

· Malwarebytes Labs · Microsoft fixes record 964 flaws, including 2 exploited zero-days · Cyber Centre Kanada · Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1

SPOJENO PŘES CVE New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]

EPSS 0.01 CVE-2026-69414 Microsoft US

tg: zranitelnost

· BleepingComputer · New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access · Malwarebytes Labs · ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw · Microsoft Security · CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability

Riasztás Microsoft szoftverek 2026 szeptemberben javított sérülékenységeiről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 974 különböző biztonsági hibát javított, köztük 2 db nulladik napi (zero-day) sebezhetőséget is, amelyet a Microsoft […]

Microsoft HU

tg: zneužíváno tg: zranitelnost

· NKI Maďarsko · Riasztás Microsoft szoftverek 2026 szeptemberben javított sérülékenységeiről

ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.

CVSS 5.8 Microsoft US

tg: zranitelnost tp: identita

· Zero Day Initiative · ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-69805, CVE-2026-58649, CVE-2026-69806, CVE-2026-69439, CVE-2026-69821, CVE-2026-69624, CVE-2026-62810, CVE-2026-69395, CVE-2026-62762, CVE-2026-62813, CVE-2026-69809, CVE-2026-69359, CVE-2026-69524, CVE-2026-69546, CVE-2026-72978, CVE-2026-57099, CVE-2026-69304, CVE-2026-69401, CVE-2026-70352, CVE-2026-62895 (+1151 other associated CVEs), Summary: Today is Microsoft's September 2026 Patch…

CVSS 10.0 Microsoft FI

tg: zneužíváno tg: zranitelnost

· NCSC-FI · Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Multiples vulnérabilités dans Microsoft Azure (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.

EPSS 0.01 CVE-2026-62895 CVE-2026-69854 CVE-2026-77909 CVE-2026-81349 CVE-2026-83948 Microsoft FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Azure (09 septembre 2026)

SPOJENO PŘES CVE Multiples vulnérabilités dans Microsoft Windows (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que les vulnérabilités CVE-2026-81963...

KEV ✓ EPSS 0.01 CVE-2026-81963 Microsoft FR US

tg: zneužíváno tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Windows (09 septembre 2026) · Microsoft Security · CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability · CISA KEV · Microsoft Windows Link Following Vulnerability (CVE-2026-81963)

Multiples vulnérabilités dans Microsoft .Net (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

EPSS 0.02 CVE-2026-58649 CVE-2026-69304 CVE-2026-69439 CVE-2026-69522 CVE-2026-69806 CVE-2026-71328 Microsoft FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft .Net (09 septembre 2026)

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and…

Microsoft US

tg: zneužíváno tg: zranitelnost

· Cisco Talos · Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

9

Patch Tuesday - September 2026

Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will…

Microsoft Google US

tg: zneužíváno tg: zranitelnost tg: přehled

· Rapid7 · Patch Tuesday - September 2026

September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS. A few vulnerabilities worth mentioning: Windows Update Stack…

KEV ✓ EPSS 0.01 CVSS 9.8 CVE-2026-66302 CVE-2026-69579 CVE-2026-69590 CVE-2026-81963 CVE-2026-85880 Microsoft US

tg: zneužíváno tg: zranitelnost

· SANS Internet Storm Ctr. · September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August…

Microsoft Adobe US

tg: zneužíváno tg: zranitelnost tg: přehled

· Qualys · Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

NCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windows

Microsoft heeft 666 kwetsbaarheden verholpen in Windows. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. Microsoft heeft voor Windows 666 kwetsbaarheden verholpen. De 32 ernstigste kwetsbaarheden bevinden zich in meerdere Windows componenten en hebben een CVSS score van 9.0 en hoger toegewezen gekregen. Kwaadwillenden met toegang tot deze componenten kunnen zonder voorafgaande…

Microsoft NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windows

NCSC-2026-0352 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Office

Microsoft heeft 114 kwetsbaarheden verholpen in diverse Office producten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. Voor succesvol misbruik moet de kwaadwillende het slachtoffer misleiden een malafide bestand te openen of link te volgen. Microsoft heeft voor Office 114 kwetsbaarheden verholpen. De 4 ernstigste kwetsbaarheden bevinden zich in meerdere Office componenten en hebben…

EPSS 0.01 CVE-2026-66302 CVE-2026-78505 CVE-2026-78509 CVE-2026-78510 Microsoft NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0352 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Office

NCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Tools

Microsoft heeft 15 kwetsbaarheden verholpen in diverse Developer Tools. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade zoals benoemd in onderstaande tabel. De ernstigste kwetsbaarheid met kenmerk CVE-2026-81376 heeft een CVSS-score van 9,6. Een kwaadwillende misbruiken door een gebruiker ertoe te verleiden een speciaal geprepareerde Visual Studio Code-workspace te openen. Hiermee kunnen de Workspace Trust-beperkingen…

EPSS 0.01 CVE-2026-57099 CVE-2026-58611 CVE-2026-58649 CVE-2026-69304 CVE-2026-70334 CVE-2026-78461 CVE-2026-78462 CVE-2026-80097 CVE-2026-81356 CVE-2026-81357 CVE-2026-81376 CVE-2026-81377 CVE-2026-81378 CVE-2026-81379 CVE-2026-81380 CVE-2026-81381 CVE-2026-81383 Microsoft NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Tools

NCSC-2026-0350 [1.00] [M/H] Kwetsbaarheden verholpen in SQL Server

Microsoft heeft 62 kwetsbaarheden verholpen in diverse componenten van SQL Server. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade zoals benoemd in onderstaande tabel. ``` SQL Server: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-47297 | 8,10 | Uitvoeren van willekeurige code | | CVE-2026-66814 | 8,80 |…

Microsoft NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0350 [1.00] [M/H] Kwetsbaarheden verholpen in SQL Server

NCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server

Microsoft heeft 9 kwetsbaarheden verholpen in Exchange Server. Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service uit te voeren, zich voor te doen als andere gebruiker, zich verhoogde rechten toe te kennen, willekeurige code uit te voeren en/of toegang te krijgen tot gevoelige gegevens. De ernstigste kwetsbaarheid met kenmerk CVE-2026-69380 heeft een CVSS-score van 9,9 en betreft een autorisatiekwetsbaarheid. Een geauthenticeerde kwaadwillende met beperkte rechten en…

EPSS 0.01 CVE-2026-55007 CVE-2026-69355 CVE-2026-69356 CVE-2026-69361 CVE-2026-69375 CVE-2026-69378 CVE-2026-69380 CVE-2026-69382 CVE-2026-69641 Microsoft NL

tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server

NCSC-2026-0348 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Dynamics

Microsoft heeft 2 kwetsbaarheden verholpen in Dynamics, zowel online als on-premise. De kwetsbaarheden stellen een kwaadwillende in staat om zich verhoogde rechten toe te kennen, willekeurige code uit te voeren en/of toegang te krijgen tot gevoelige gegevens. ``` Microsoft Dynamics 365: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65772 | 8,80 | Uitvoeren van willekeurige…

EPSS 0.01 CVE-2026-65772 CVE-2026-77897 Microsoft NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0348 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Dynamics