CVE-2026-69605 Microsoft Install Service Elevation of Privilege Vulnerability
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69605 Microsoft US
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69605 Microsoft US
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69594 Microsoft US
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69608 Microsoft US
Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69585 Microsoft US
Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-69554 Microsoft US
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-69507 Microsoft US
Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.
EPSS 0.00 CVE-2026-69531 Microsoft US
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69491 Microsoft US
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-69420 Microsoft US
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69408 Microsoft US
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-69367 Microsoft US
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-69345 Microsoft US
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69336 Microsoft US
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69325 Microsoft US
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-69276 Microsoft US
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68892 Microsoft US
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-69271 Microsoft US
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68890 Microsoft US
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
EPSS 0.00 CVE-2026-68881 Microsoft US
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-68897 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-68787 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-68785 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68784 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68781 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-67633 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67631 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67630 Microsoft US
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-67629 Microsoft US
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-67373 Microsoft US
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-67370 Microsoft US
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-67368 Microsoft US
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-55007 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
EPSS 0.01 CVE-2026-62801 Microsoft US
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-57098 Microsoft US
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-77482 Microsoft US
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-62744 Microsoft US
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-62706 Microsoft US
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…
KEV ✓ EPSS 0.02 CVE-2026-75650 CVE-2026-81963 CVE-2026-85880 CVE-2026-86218 Adobe Magento Microsoft N-able veřejná správa US
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.
EPSS 0.05 CVSS 7.8 CVE-2026-66804 Microsoft US
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.
EPSS 0.00 CVSS 7.8 CVE-2026-62712 Microsoft US
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.
EPSS 0.01 CVSS 8.1 CVE-2026-50696 Microsoft US
Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps the AD RMS trust model (the Server Licensor Certificate, the license flow, the SOAP surface) and shows how to discover an RMS deployment, fingerprint an AD RMS-protected file, and trace the path to that certificate's private key.
Microsoft US
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
Microsoft US
Introduction We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In early July 2026, we observed the group using a custom backdoor for the first time. We…
Microsoft RU
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Microsoft FR
Your security data is the most important asset in your SOC. Not the dashboards, not the detections, not the AI features on the roadmap slide. The data. And most vendors make you pay, wait, or license your way to getting it back out. Every investigation your analysts run, every model you train, every agent you deploy is only as good as the telemetry underneath it. So here is the question I want you to ask every vendor in your stack: if I want my data, right now, what does that take?Most vendors…
In this article What is ASCII smuggling?Writing a practical ASCII-smuggling signatureWhat we observed: ASCII smuggling repurposed for phishingWhat is known and what is newIs there a detection gap?Mitigation and protection guidanceReferencesLearn More Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people…
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-62916 Microsoft US
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-83711 Microsoft US
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-70178 Microsoft US
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-62906 Microsoft US
First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be. California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027. Operating…
In this article Risk to enterprise environmentsAttack chain overviewMitigation and response recommendationsLearn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI…
Microsoft US
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal. Detection catches the move; posture management explains why it was…
Microsoft US
Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes from Malwarebytes’ own threat research systems and…
Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…
EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]
In this article What is the Cybersecurity Incident Response Readiness Workshop?Our approach: How we assess your maturityLearn more Cybersecurity incidents can unfold in hours, but response plans often fail at the point of execution: ownership is unclear, investigation findings is difficult to access, and critical decisions are delayed. That is why incident response cannot be something your organization figures out in real time. The Detection and Response Team (DART) – the Microsoft team that…
Microsoft US
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
KEV ✓ EPSS 0.72 CVE-2026-42897 CVE-2026-62911 Microsoft US
Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A website visitor is presented with a fake Cloudflare CAPTCHA which, when clicked, secretly copies a malicious command to their clipboard. Then they receive instructions on what they need to do to “prove they are human,” when in reality they are being instructed to execute the malicious command. After…
Microsoft US