Today's Top Windows System Articles for 2026-07-15


Articles for the IT Professional. Today's edition includes 150 articles from 28 sites. We chose these from 8269 articles found on 136 sites.


Today's featured sites are:
Fast Company - technology, www.theregister.com - Articles, IEEE Spectrum, HTMD Community Intune Windows Modern Workplace Device Management, Radar, Computerworld, Irish Tech News, 9to5Mac, darkreading, AppleInsider News, Check Point Research, VentureBeat, Petri IT Knowledgebase, New blog articles in Microsoft Community Hub, Windows 10 Help Forums, Krebs on Security, Ars Technica - All content, TechPlanet, Microsoft Security Blog, Techdirt, GeekWire, Neowin, Ars Technica, CNET, EdSurge Articles, Windows Latest, MSRC Security Update Guide, BleepingComputer.

Article Keywords: entra, sso, script

This new AI model thinks in images, not just words

For almost a decade, AI researchers have been obsessed with one kind of artificial intelligence—large language models (LLMs), which they train to write, talk, and reason using words. The tech industry...


Fast Company - technology
Jul 13, 2026 - fastcompany.com
Article Keywords: rsat, entra, critical, issue, latency, routing, automation

AI needs a home, not a hotel

PARTNER CONTENT: Firms crafting internal AI must choose a permanent residence for their tech, not just rent server space by the hour.


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: entra, fix, error, latency, pipeline

Building a Foundation Stack for General-Purpose Robots

This article is brought to you by X Square Robot.Large language models gave artificial intelligence a working recipe. Pretrain a large model on broad data, and general capability follows. Robotics has...


IEEE Spectrum
Jul 13, 2026 - spectrum.ieee.org
Article Keywords: kerberos, intune, sccm

Use Intune to Strengthen Authentication Security by Managing Kerberos Certificate Hash Algorithms

Hello - Here is the new HTMD Blog Article for you. Enjoy reading it. Subscribe to YouTube Channel https://www.youtube.com/c/AnoopCNairSCCM?sub_confirmation=1 and LinkedIn page for latest updates htt...


HTMD Community Intune Windows Modern Workplace Device Management
Jul 13, 2026 - anoopcnair.com
Article Keywords: vulnerability::2, defender::2, attack surface::2, critical, issue, automation

Exclusive: 34 CEOs on what thrills and terrifies them about agentic AI 

When businesses leaders think about AI right now, they’re thinking about how agentic tools will change the very nature of their work. “We’ve crossed a line,” says Varun Krishna, CEO of the fintech gia...


Fast Company - technology
Jul 13, 2026 - fastcompany.com
Article Keywords: review::-3, alert, issue, bug, error, failed, script

The Frontend Verification Gap in AI-Assisted Development

AI-assisted development has made frontend work feel much faster. A developer can ask for a form, a dashboard card, a table, a modal, or a responsive layout and get a decent first version almost immedi...


Radar
Jul 13, 2026 - oreilly.com
Article Keywords: review::-3, entra, fix, issue, troubleshoot, error, automation, pipeline

Q&A: How Google plans to reinvent the spreadsheet with AI

Nearly five decades after the launch of VisiCalc, AI is reshaping one of the world’s most familiar productivity tools — the humble spreadsheet. While a lot of knowledge workers interact with spreads...


Computerworld
Jul 13, 2026 - computerworld.com
Article Keywords: critical, script

New York City’s chief technologist is launching a new team to transform the city’s technology

New York City may soon undergo a major technological revamp. Earlier today, the mayor’s office announced it had begun hiring for a new group that will travel across city agencies and deploy technologi...


Fast Company - technology
Jul 13, 2026 - fastcompany.com
Article Keywords: rsat, breaking, sso

Ireland’s first Renewable Energy Workforce & Skills Survey

An early snapshot of a new survey into Ireland’s renewable energy sector points to emerging skills bottlenecks and challenges recruiting experienced talent across parts of the sector. Solar Ireland ha...


Irish Tech News
Jul 13, 2026 - irishtechnews.ie
Article Keywords: breaking, issue

Free Mac app WhatCable tells you what each of your USB-C cables can really do

We’ve talked on a number of occasions about the problem with USB-C cables: namely, they all look alike but can have very different capabilities. Google addressed this issue in Chrome OS several years ...


9to5Mac
Jul 13, 2026 - 9to5mac.com
Article Keywords: breaking, pipeline

New green and renewable hydrogen developments for decarbonisation

Lhyfe one of the world’s pioneers in the production of green and renewable hydrogen for decarbonisation, is strengthening its logistics capabilities, which since 2021 have supported some sixty or so i...


Irish Tech News
Jul 13, 2026 - irishtechnews.ie
Article Keywords: windows server, exploit::2, ransomware::2, remote code execution::2, critical, warning, incident, bug, workaround

Progress orders emergency ShareFile server shutdown over mystery security threat

Vendor insists there's no evidence of unauthorized access, but it's asking customers to take one of the most drastic precautions available


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: phishing::2

Turning the Tables on Email Scammers With 'ScamBuster'

An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.


darkreading
Jul 13, 2026 - darkreading.com
Article Keywords: warning, sso

'CrashStealer' malware poses as an Apple tool to steal passwords & Mac data

CrashStealer, a newly documented Mac infostealer, used an Apple-notarized meeting app to reach victims before stealing passwords, browser data and cryptocurrency credentials behind a fake system promp...


AppleInsider News
Jul 13, 2026 - appleinsider.com
Article Keywords: rsat, cve::2, vulnerability::2, exploit::2, ransomware::2, phishing::2, remote code execution::2, critical, incident, issue, proxy, sso, script

13th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a da...


Check Point Research
Jul 13, 2026 - research.checkpoint.com
Article Keywords: dns, bug, failed, firewall, load balancer, gateway, sso, script

HTTP gets a QUERY method so complex searches can stop pretending to be POST

New verb carries request content while remaining safe, idempotent, and cacheable


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: registry, exploit::2, attack surface::2

Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools

Slopsquatting represents an emerging supply chain threat made possible by AI hallucinations. As developers increasingly rely on AI coding assistants, they unknowingly grant cybercriminals access to th...


VentureBeat
Jul 13, 2026 - venturebeat.com
Article Keywords: powershell, microsoft 365, exchange online

Exchange Online to Add Cross-Tenant Message Recall with Admin-Controlled Trust

Microsoft is adding Cross-Tenant Message Recall to Exchange Online, allowing organizations to recall mistakenly sent emails across trusted Microsoft 365 tenants. The new capability extends one of Exch...


Petri IT Knowledgebase
Jul 13, 2026 - petri.com
Article Keywords: dns, azure, outage, incident, fix, failed, latency, subnet, script, pipeline

A message broker is only as reliable as the layer you stopped at

Reliability is easy to reduce to a single number. You find the SLA, you put it on a slide, and you move on. But a service-level agreement describes an outcome, not the set of decisions that produce it...


New blog articles in Microsoft Community Hub
Jul 13, 2026 - techcommunity.microsoft.com
Article Keywords: incident, sso

World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection

Footie fans? Overreacting? There's a first time for everything


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: fix, troubleshoot

Qs Concerning De-Bloating Win 10 Pro and Win 11 Pro

Considering using Chris Titus Tool on multiple Win 10 Pro and single Win 11 Pro computers. Will use "suggested" settings. First, any known negatives doing this? Second, I'm assuming buying a copy ...


Windows 10 Help Forums
Jul 13, 2026 - tenforums.com
Article Keywords: vulnerability::2, incident, alert, issue, bug, sso

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys --...


Krebs on Security
Jul 13, 2026 - krebsonsecurity.com
Article Keywords: defender::2

Now, defenders are embracing the prompt injection, too

"Context bombing" tricks hacking agents into shutting down before they can do harm.


Ars Technica - All content
Jul 13, 2026 - arstechnica.com
Article Keywords: cve::2, vulnerability::2, critical

GhostLock: The Critical Linux Kernel Vulnerability That Existed for 15 Years

Introduction In July 2026, security researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a critical vulnerability in the Linux kernel that had existed undetected for over 15 years. The...


TechPlanet
Jul 13, 2026 - techplanet.today
Article Keywords: price::-3, bug, error, failed, routing, pipeline

ACRouter picks the smartest AI model per task, beating Opus-only setups by 2.6x on cost

Model routing is becoming a key component of the enterprise AI stack, dynamically sending prompts to the right AI model to optimize speed and costs. However, current frameworks mostly treat routing as...


VentureBeat
Jul 13, 2026 - venturebeat.com
Article Keywords: fix, troubleshoot

Loss of sound

The desktop PC I'm currently using has no sound output whatsoever. I'm pretty sure this is a result of something I've done. Please bear with me because this has been ongoing for a number of weeks and ...


Windows 10 Help Forums
Jul 13, 2026 - tenforums.com
Article Keywords: price::-3, rsat, issue, bug, script, pipeline

Sticker shock has execs rethinking this whole AI thing

This week on The Reg's Kettle podcast, we wonder whether tokenminning is going to bring the industry back down to Earth


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: review::-3, dns, azure, resolution, error, dns resolution, gateway, subnet, routing, sso

Lessons Learned #543: Evaluating MultiSubnetFailover with Azure SQL Database

Last week, I worked on a support case in which the use of the MultiSubnetFailover connection-string feature was being considered for an application connecting to Azure SQL Database.  The expectation w...


New blog articles in Microsoft Community Hub
Jul 13, 2026 - techcommunity.microsoft.com
Article Keywords: fix, sso

Hackers quickly prove that Neo Geo Doom ports are not "impossible"

Clever coding and graphical compromises get a classic game on more classic hardware.


Ars Technica - All content
Jul 13, 2026 - arstechnica.com
Article Keywords: rdp, breaking

WordPress just released a brand-new Apple TV app with thousands of free videos

It’s not every day that a new Apple TV app arrives for tvOS. WordPress just released WordPress TV, bringing video content to the big screen.


9to5Mac
Jul 13, 2026 - 9to5mac.com
Article Keywords: review::-3, entra, phishing::2, privilege escalation::2, security update::2, lateral movement::2, credential theft::2, urgent, sso

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: P...


Microsoft Security Blog
Jul 13, 2026 - microsoft.com
Article Keywords: review::-3, autopilot, outage, incident, alert, fix, issue, automation

SREs to AI agents: Prove yourself before you touch production

SPONSORED FEATURE: 696 experts find co-pilot welcome, autopilot not so much


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: cve::2, zero-day::2, vulnerability::2, exploit::2, defender::2, fix, issue

Microsoft Patches Zero-Day RoguePlanet Defender Flaw that Allows SYSTEM-Level Access

Microsoft has released an update to address a zero-day RoguePlanet vulnerability in Microsoft Defender. This security flaw, CVE-2026-50656, can be exploited by hackers to gain full access to the victi...


Petri IT Knowledgebase
Jul 13, 2026 - petri.com
Article Keywords: windows server, registry, rsat, azure, entra, defender for endpoint, defender for cloud, cve::2, vulnerability::2, exploit::2, security update::2, defender::2, critical, alert, fix, workaround, azure arc, script

Patch the Kernel, Skip the Reboot: The Case for Arc-Enabled Hotpatching on Windows Server 2025

For decades, applying a security fix to core OS components meant swapping files on disk and restarting so the loader could map the new image into memory. Rebooting to patch is a workaround for a limit...


New blog articles in Microsoft Community Hub
Jul 13, 2026 - techcommunity.microsoft.com
Article Keywords: vulnerability::2, exploit::2, security update::2, defender::2, critical, urgent, warning, alert, advisory, issue, proxy, sso

EU and UK officially blame Russian spies for cyberattack on Poland's power grid

Sweeping sanctions and condemnation follow op that could have left half a million without power in the depths of winter


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: fix, issue, troubleshoot

Surface 3 running windows 10 locks up

I have a Surface 3 that I have purchased when they first came out. Lately when I turn it on after a few minutes it locks up and that I have hold down the on button to turn it off. Today I held down Wi...


Windows 10 Help Forums
Jul 13, 2026 - tenforums.com
Article Keywords: incident, issue, sso

Philips to replace bricked Hue Bridge Pro devices

Company releases a fresh firmware update. Go on, install it, we dare you...


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: issue, firewall

Trump Admin Supoenas NYT Reporters Because They Dared To Criticize His Qatari Graft Plane

Less than a month ago, Trump secured himself a $400 million plane for free — something he certainly couldn’t have accomplished if he weren’t the president of the United States. It’s no longer a mere a...


Techdirt
Jul 13, 2026 - techdirt.com
Article Keywords: ransomware::2, outage

German firm files for insolvency, blames cybercrims who shut down production for 6 weeks

ZEGO-TVZ says the financial fallout from a March cyberattack left shutting its doors as the only option


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: issue, sso

Solution to Feynman's reverse sprinkler puzzle also applies to "silly sprinklers"

New study confirms 2024 "momentum flux theory" on how angular momentum of water flows drives rotation.


Ars Technica - All content
Jul 13, 2026 - arstechnica.com
Article Keywords: review::-3, azure, defender for endpoint, defender::2, lateral movement::2, critical, incident, alert, automation

Building toward an Agentic SOC: A Portable, Autonomous Malware Investigation Agent

Modern Security Operations Centers are not short on tools. They are short on continuity. Analysts jump from alert consoles to data exploration, from enrichment to investigation, and from evidence gath...


New blog articles in Microsoft Community Hub
Jul 13, 2026 - techcommunity.microsoft.com
Article Keywords: azure, microsoft 365, sharepoint, warning

Microsoft chief turns hostile on frontier AI labs, warns companies to guard their IP

Lock it down, warns Satya Nadella, seemingly forgetting the billions Redmond chipped in to OpenAI back in the good old days


www.theregister.com - Articles
Jul 13, 2026 - theregister.com
Article Keywords: breaking, sso

Apple TV has a packed lineup of sports premieres coming soon

From pickleball and college basketball to the return of Ted Lasso, Apple TV has a packed sports lineup arriving over the next few weeks. Here’s everything coming up.


9to5Mac
Jul 13, 2026 - 9to5mac.com
Article Keywords: breaking, issue, bug

MagSafe Monday: The Twelve South PowerBug clears your counters

The only issue with MagSafe is that a cable is still required at home. Twelve South decided to tackle this problem by eliminating the cable entirely and taking cues from the MagSafe battery market. Th...


9to5Mac
Jul 13, 2026 - 9to5mac.com
Article Keywords: entra, exploit::2, breaking, sso

Grunge meets slop: An AI time traveler visits 1992 Seattle when music, not tech, ruled the city

The AI-generated video is an interesting study in how technology that's very much being built and hyped in Seattle can be used to illustrate what the city sort of looked like more than three decades a...


GeekWire
Jul 13, 2026 - geekwire.com
Article Keywords: fix, issue, bug

New Forza Horizon 6 update fixes bugs with in-game AI and resets the Rivals Leaderboards

Have you been experiencing any issues with Forza Horizon 6 lately? Check out if the latest update fixes your problems. Read more...


Neowin
Jul 13, 2026 - neowin.net
Article Keywords: review::-3, discount::-3, comparison::-3, windows server, group policy, gpo, dns, dhcp, powershell, rdp, azure, entra, intune, microsoft 365, defender for endpoint, vulnerability::2, phishing::2, defender::2, critical, alert, fix, issue, known issue, resolution, troubleshoot, error, latency, firewall, dns resolution, routing, azure arc, conditional access, sso, zero trust, automation, script, ci/cd, pipeline, infrastructure as code, iac, terraform, bicep

Check This Out! (CTO!) Guide (July 2026)

Member: TysonPaul | Microsoft Community Hub Triage vulnerabilities with the Vulnerability Remediation Agent, now in public preview Team Blog: Intune Customer Success Author: Intune_Support_Team Publi...


New blog articles in Microsoft Community Hub
Jul 13, 2026 - techcommunity.microsoft.com
Article Keywords: exploit::2, critical, warning, advisory, issue, proxy

The US government warns that Russia state hackers are coming after your router

With residential proxies all the rage, CISA urges router users to be vigilant.


Ars Technica - All content
Jul 13, 2026 - arstechnica.com
Article Keywords: review::-3, exploit::2, critical, warning, advisory, issue, proxy

The US government warns that Russia state hackers are coming after your router

With residential proxies all the rage, CISA urges router users to be vigilant.


Ars Technica
Jul 13, 2026 - arstechnica.com
Article Keywords: issue, sso

Apple Is Reportedly Accelerating Chip Releases Due to AI Pressure

According to a report, the company plans to skip higher-performance versions of some of its processors along the way.


CNET
Jul 13, 2026 - cnet.com
Article Keywords: entra, critical, issue

OpenClaw becomes a nonprofit foundation as it seeks to be ‘the Switzerland of AI’

OpenClaw’s announcement that it has become a nonprofit foundation is generating IT excitement because of the potential for governance and development consistency that the popular platform has thus far...


Computerworld
Jul 13, 2026 - computerworld.com
Article Keywords: review::-3, microsoft 365, defender for cloud, vulnerability::2, exploit::2, phishing::2, defender::2, attack surface::2, lateral movement::2, critical, incident, alert, sso, zero trust, script

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misco...


Microsoft Security Blog
Jul 13, 2026 - microsoft.com
Article Keywords: rsat, entra, issue, sso

We Talk About Whole Children. What About Whole Educators?

We treat early childhood teachers like babysitters instead of the engineers they are. If we want them to stay, we have to invest in the systems that ...


EdSurge Articles
Jul 14, 2026 - edsurge.com
Article Keywords: rsat, federation, sso

Anthropic Introduces Claude for Teachers

The AI rollout is the latest effort by a tech giant to win over educators and districts.


EdSurge Articles
Jul 14, 2026 - edsurge.com
Article Keywords: review::-3, group policy, microsoft 365, zero-day::2, vulnerability::2, exploit::2, patch tuesday::2, fix, issue, bug

Microsoft warns not to delay Windows 11 updates past three days, AI can exploit bugs in hours

Microsoft warned that it no longer recommends delaying Windows 11 updates for more than three days due to AI. The post Microsoft warns not to delay Windows 11 updates past three days, AI can exploit b...


Windows Latest
Jul 14, 2026 - windowslatest.com
Article Keywords: hands-on::-3, rsat, exploit::2, phishing::2, attack surface::2

AI Security Report 2026

For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual ...


Check Point Research
Jul 14, 2026 - research.checkpoint.com
Article Keywords: cve::2, security update::2

CVE-2026-40553 Stack-based buffer overflow in gawk

Information published.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, security update::2

CVE-2026-40469 Heap buffer overflow in gawk

Information published.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, security update::2

CVE-2026-40468 Heap buffer overflow in gawk

Information published.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, security update::2

CVE-2026-40467 Use after free in gawk

Information published.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: review::-3, fix, issue, bug, error, script

Zig creator calls Bun’s Claude Rust rewrite ‘unreviewed slop’

The port took just 11 days and about $165,000 at API pricing


www.theregister.com - Articles
Jul 14, 2026 - theregister.com
Article Keywords: azure, failed

Zuck's AI ambitions put Meta on course to become America's next big cloud provider

Renting out spare compute is simply the natural progression for any sufficiently large infra company


www.theregister.com - Articles
Jul 14, 2026 - theregister.com
Article Keywords: cve::2, security update::2

CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras

Information published.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, security update::2

CVE-2026-14461 Out-of-bound read in mtr

Information published.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: entra, fix, sso

Gobi X: Creating more energy for AI, not taking it from society

PARTNER CONTENT: How Envision is reversing the datacenter playbook by making computing chase abundant desert power, not the other way around


www.theregister.com - Articles
Jul 14, 2026 - theregister.com
Article Keywords: review::-3,  vs ::-3, registry, azure, entra, attack surface::2, fix, issue, proxy, gateway, routing, script, pipeline, iac, terraform

From Multi-Model Chaos to a Governed AI Gateway: Cost Optimization on Azure

What is Multi-Model Chaos, and what cost and security challenges does it pose?  Multi-model chaos describes the sprawl that emerges when an organization rapidly adopts many large language and foundati...


New blog articles in Microsoft Community Hub
Jul 14, 2026 - techcommunity.microsoft.com
Article Keywords: ransomware::2, vpn

US sanctions VPN, malware providers for enabling ransomware attacks

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. [...]


BleepingComputer
Jul 14, 2026 - bleepingcomputer.com
Article Keywords: defender::2

New Microsoft Defender update can let hackers totally fill your Windows 11 PC disk space

A recent Microsoft Defender update can reportedly allow hackers to completely consume your Windows 11 PC's disk space. Here's how. Read more...


Neowin
Jul 14, 2026 - neowin.net
Article Keywords: hands-on::-3, rsat, azure, entra, microsoft 365, sharepoint, onedrive, purview

Event Recap - TechCon Chicago 2026

TechCon 365 Chicago is part of the TechCon series of regional Microsoft 365, Power Platform, and Azure data conferences — one of the most widely attended community-run Microsoft conference series in N...


New blog articles in Microsoft Community Hub
Jul 14, 2026 - techcommunity.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability

Updated FAQ information. This is an informational change only.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-48561 Microsoft Copilot Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-42982 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-47296 Microsoft SQL Server Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-34349 Windows Media Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-34346 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-42900 Microsoft Windows App Store Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, remote code execution::2, security update::2

CVE-2026-42975 Windows Bluetooth Port Driver Remote Code Execution

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-47300 ASP.NET Core Elevation of Privilege Vulnerability

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-47302 .NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-47303 ASP.NET Core Elevation of Privilege Vulnerability

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-42990 SQL Server ODBC driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-48572 Windows App Package Installer Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-48571 Windows App Package Installer Elevation of Privilege Vulnerability

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: active directory, cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-49164 Windows Active Directory Domain Services Remote Code Execution Vulnerability

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49165 Microsoft Windows App Store Information Disclosure Vulnerability

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49166 Windows Print Configuration Elevation of Privilege Vulnerability

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: dns, cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-49169 Windows DNS Server Remote Code Execution Vulnerability

Use after free in DNS Server allows an authorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49170 Windows StateRepository API Server file Elevation of Privilege Vulnerability

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49171 Windows Speech Runtime Elevation of Privilege Vulnerability

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49176 Windows WalletService Elevation of Privilege Vulnerability

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: dns, cve::2, vulnerability::2, security update::2

CVE-2026-49175 Windows DNS Client Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-49172 Windows FTP Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49173 Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: dns, cve::2, vulnerability::2, security update::2, critical

CVE-2026-49174 DNS Client Tampering Vulnerability

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2, tcp/ip

CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability

Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-49784 Microsoft Windows App Store Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-50506 OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-45496 Visual Studio Code Security Feature Bypass Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-50663 Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability

Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: active directory, cve::2, vulnerability::2, security update::2, federation

CVE-2026-54983 Windows Active Directory Federation Services Denial of Service Vulnerability

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: active directory, cve::2, vulnerability::2, security update::2, federation

CVE-2026-50695 Windows Active Directory Federation Services Denial of Service Vulnerability

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: hyper-v, cve::2, vulnerability::2, security update::2

CVE-2026-54129 Windows Hyper-V Elevation of Privilege Vulnerability

Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54989 Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability

Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54987 Windows Overlay Filter Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: remote desktop, cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54990 Remote Desktop Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability

Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54111 Universal Print Management Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54991 Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54132 Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54107 Windows Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54986 Windows Win32k Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54993 Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: active directory, cve::2, vulnerability::2, security update::2

CVE-2026-55001 Active Directory Domain Services Elevation of Privilege Vulnerability

Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54112 Windows Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-55004 Windows Print Configuration Elevation of Privilege Vulnerability

Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54992 Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54109 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54982 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54114 Windows Win32k Elevation of Privilege Vulnerability

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54996 Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: active directory, cve::2, vulnerability::2, security update::2

CVE-2026-54119 Windows Active Directory Denial of Service Vulnerability

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: smb, cve::2, vulnerability::2, security update::2

CVE-2026-54997 Windows SMB Information Disclosure Vulnerability

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2, tcp/ip

CVE-2026-54999 Windows TCP/IP Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: remote desktop, rdp, cve::2, vulnerability::2, security update::2

CVE-2026-55003 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54995 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54122 Windows GDI+ Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-55005 Microsoft Exchange Server Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-55006 Microsoft Exchange Server Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-55009 Microsoft Exchange Server Elevation of Privilege Vulnerability

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: azure, cve::2, vulnerability::2, security update::2

CVE-2026-50338 Azure Spring Apps Elevation of Privilege Vulnerability

Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2, defender::2

CVE-2026-55011 Microsoft Defender Remote Code Execution Vulnerability

Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2, defender::2

CVE-2026-55012 Microsoft Defender Remote Code Execution Vulnerability

Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-50524 .NET Framework Denial of Service Vulnerability

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-55002 Microsoft SQL Server Elevation of Privilege Vulnerability

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-55144 Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability

Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-50520 Visual Studio Code Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: sharepoint, cve::2, vulnerability::2, security update::2

CVE-2026-54108 Microsoft SharePoint Server Spoofing Vulnerability

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-50675 Microsoft Excel Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-50678 Microsoft Excel Information Disclosure Vulnerability

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, security update::2

CVE-2026-54988 Microsoft Excel Information Disclosure Vulnerability

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-55899 Microsoft Excel Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com
Article Keywords: cve::2, vulnerability::2, remote code execution::2, security update::2

CVE-2026-55948 Microsoft Excel Remote Code Execution Vulnerability

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.


MSRC Security Update Guide
Jul 14, 2026 - msrc.microsoft.com