PatchSiren

Microsoft CVE debriefs · Page 43

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50304

A stack-based buffer overflow vulnerability exists in Active Directory Federation Services, potentially allowing an unauthorized attacker to deny service over a network. The CVE record was published on 2026-07-14T18:17:28.220Z and was last modified on 2026-07-16T19:42:19.223Z. This vulnerability, tracked under CWE-121, has a CVSS score of 7.5 with a severity of HIGH. System administrators and security pro [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-50302

CVE-2026-50302 is a MEDIUM severity vulnerability in Windows Cryptographic Services, classified as CWE-295. The vulnerability allows an unauthorized attacker to bypass a security feature over a network due to improper certificate validation. The CVE record was published on 2026-07-14T18:17:28.010Z and has not been modified since then. System administrators and security teams should be aware of this vulner [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-50301

CVE-2026-50301 is a high-severity vulnerability in Microsoft Office, allowing unauthorized attackers to execute code locally via a heap-based buffer overflow. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft Office 2016, 2019, 2021, and 2024 are affected, with various architectures and platforms impacted. This vulnerability could allow an attacker to execute arbitrary code on [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-47642

A use-after-free vulnerability in Microsoft Office Excel allows an unauthorized attacker to execute code locally. This CVE record was published on 2026-07-14T18:17:18.550Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability is a use-after-free issue in Microsoft Office Excel, which occurs when a program tries to use memory after it has been freed or deleted. An att [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-47295

A high-severity SQL injection vulnerability exists in Microsoft SQL Server, tracked as CVE-2026-47295. This vulnerability allows an authorized attacker to elevate privileges over a network by improperly neutralizing special elements used in an SQL command. The vulnerability affects multiple versions of SQL Server, including 2016, 2017, 2019, 2022, and 2025. Organizations should prioritize patching this vu [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-47290

CVE-2026-47290 is a high-severity vulnerability in Microsoft Office, allowing unauthorized attackers to execute code locally via a use-after-free exploit. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft Office 2016, 2019, 2021, and 2024 are affected, with various architectures and platforms impacted. The exploit requires user interaction, with CVSS vector CVSS:3.1/AV:L/AC:L/ [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58640

A high-severity vulnerability, CVE-2026-58640, has been identified in Windows NTFS, which could allow an authorized attacker to execute code locally. This vulnerability is caused by a heap-based buffer overflow. The vulnerability has a CVSS score of 7.3 and is classified as HIGH severity. The vulnerability affects Windows operating systems and could be exploited by an authorized attacker to execute code l [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58636

CVE-2026-58636 is a HIGH severity vulnerability in Microsoft's PC Manager, with a CVSS score of 7.8. The vulnerability is caused by improper link resolution before file access, also known as 'link following', which allows an authorized attacker to elevate privileges locally. The vulnerability exists in the PC Manager software, which is developed by Microsoft. This vulnerability has a significant impact on [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58635

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:17:13.833Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability, CVE-2026-58635, is a command injection vulnerability in Windows Narrator Braille, allowing an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 a [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58631

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:17:13.717Z and has not been modified since then. This HIGH severity vulnerability in Windows Admin Center, with a CVSS score of 7.8, is caused by improper authorization, allowing an authorized attacker to execute code locally. System administrators and security teams responsible for Windows Ad [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58618

A high-severity vulnerability, CVE-2026-58618, was found in Microsoft Office Excel. This heap-based buffer overflow vulnerability allows an unauthorized attacker to execute code locally. The CVE record was published on 2026-07-14T17:17:13.587Z and has not been modified since then. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Multiple CPE criteria are listed, including Micr [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-58614

CVE-2026-58614 is a MEDIUM severity vulnerability in Windows Kernel, an out-of-bounds read vulnerability that allows an authorized attacker to bypass a security feature locally. The vulnerability has a CVSS score of 5.5 and a CVSS severity of MEDIUM. System administrators and security teams responsible for Windows Kernel systems should be aware of this vulnerability and review the supplied official adviso [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58610

CVE-2026-58610 is a high-severity vulnerability in Microsoft Windows Media Foundation that allows an unauthorized attacker to execute code locally. The vulnerability is caused by a heap-based buffer overflow. This type of vulnerability typically occurs when user input is not properly validated, allowing attackers to inject malicious data into the application's memory. The vulnerability's impact is signifi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58609

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:17:13.097Z and has not been modified since then. This out-of-bounds read vulnerability in Microsoft Graphics Component allows an unauthorized attacker to execute code locally, classified as HIGH severity with a CVSS score of 7.8. Users of Microsoft Graphics Component should prioritize patching [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58608

CVE-2026-58608 is a high-severity vulnerability in Windows Print Spooler Components caused by a race condition. This concurrency issue occurs when multiple processes try to access a shared resource without proper synchronization, allowing an authorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Multiple Windows versions are affected, inclu [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58602

CVE-2026-58602 is a high-severity vulnerability in Windows Kernel Mode Driver that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. Microsoft has released a patch for this vulnerability. The vulnerability is a use-after-free issue in the Windows Kernel Mode Driver. An authorized attacker can exploit this vulnerability to elev [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58601

A high-severity vulnerability, CVE-2026-58601, exists in the Virtual Hard Disk (VHD) Miniport Driver. This vulnerability is a heap-based buffer overflow that allows an authorized attacker to elevate privileges locally. The CVE record was published on 2026-07-14T17:17:12.657Z and has not been modified since then. The vulnerability has a CVSS score of 7.8 and a severity of HIGH. The affected products includ [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58595

The Microsoft Bing App for IOS is affected by a vulnerability CVE-2026-58595, which allows an unauthorized attacker to perform spoofing over a network due to improper restriction of rendered UI layers or frames. This vulnerability has a high severity level with a CVSS score of 8.1. Users of the Microsoft Bing App for IOS should apply necessary updates to prevent potential spoofing attacks. The CVE record [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-58526

CVE-2026-58526 is a high-severity vulnerability in Windows Storage that allows an authorized attacker to elevate privileges locally. The vulnerability is caused by a use-after-free issue. This vulnerability affects Windows 10, Windows 11, and Windows Server systems. Administrators and users should be aware of this vulnerability and take necessary precautions. The CVSS score for this vulnerability is 7, in [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-58279

CVE-2026-58279 is a medium-severity vulnerability in Azure CycleCloud, caused by missing authorization. This allows an authorized attacker to elevate privileges over a network. The CVSS score is 6.5, with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. The vulnerability is classified under CWE-862. Security teams and administrators responsible for Azure CycleCloud should assess the vulnerability [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-57979

CVE-2026-57979 is an out-of-bounds read vulnerability in Windows RDP that allows an unauthorized attacker to disclose information over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Microsoft has released a patch for this vulnerability. The vulnerability exists in the Windows RDP component, allowing an attacker to exploit it and disclose sensitive information. Organizations [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-57976

CVE-2026-57976 is a medium-severity vulnerability in Active Directory Domain Services that allows an authorized attacker to deny service over a network. The vulnerability has a CVSS score of 6.5 and a CVSS severity of MEDIUM. The CVE record was published on 2026-07-14T17:17:11.120Z and was last modified on 2026-07-20T17:03:42.443Z. This vulnerability is caused by a null pointer dereference in Active Direc [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-57969

CVE-2026-57969 is a high-severity vulnerability in Azure CycleCloud, allowing an authorized attacker to elevate privileges over a network due to missing authentication for a critical function. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. The vulnerability stems from a missing authentication mechanism for a critical function in Azure CycleCloud, which could allow an author [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-57107

CVE-2026-57107 is a HIGH-severity vulnerability in Windows Admin Center due to improper authentication, allowing authorized attackers to elevate privileges locally. The vulnerability has a CVSS score of 7.8. It was published on 2026-07-14T17:17:10.860Z and has not been modified since then. Security teams responsible for Windows Admin Center should assess and mitigate this vulnerability to prevent local pr [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-57097

CVE-2026-57097 is a MEDIUM severity vulnerability with a CVSS score of 6.4. It is caused by an untrusted search path in Microsoft XML, which allows an unauthorized attacker to bypass a security feature with a physical attack. The CVE record was published on 2026-07-14T17:17:10.630Z and has not been modified since. This vulnerability affects multiple versions of Microsoft Windows and Windows Server. Users [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-56193

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T17:17:10.377Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-56193 is an out-of-bounds read vulnerability in Microsoft Office that allows an unauthorized attacker to disclose information locally. The vulnerability has a CVSS score of 7.1 and is classified as H [truncated]

MEDIUM Microsoft CVE published 2026-07-14

CVE-2026-56185

CVE-2026-56185 is a MEDIUM severity vulnerability in Windows Admin Center, with a CVSS score of 6.5. It allows an authorized attacker to disclose information over a network due to improper authentication. The vulnerability was published on 2026-07-14T17:17:10.257Z and has not been modified since then. Security teams responsible for Windows Admin Center should assess and mitigate CVE-2026-56185. The CVE re [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-56170

A high-severity vulnerability CVE-2026-56170 was found in ASP.NET Core, which allows an unauthorized attacker to deny service over a network. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. Microsoft .NET versions 8.0.0 to 8.0.29, 9.0.0 to 9.0.18, and 10.0.0 to 10.0.6 are affected. The vulnerability is caused by allocation of resources without limits or throttling in ASP.NET Core. Thi [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-56169

CVE-2026-56169 is a HIGH-severity vulnerability in Windows Admin Center due to improper authentication. An authorized attacker can exploit this over a network to elevate privileges. The vulnerability is tracked under CWE-287. Security teams responsible for Windows Admin Center should assess and mitigate CVE-2026-56169. The CVE record was published on 2026-07-14T17:17:10.027Z and has not been modified sinc [truncated]

HIGH Microsoft CVE published 2026-07-14

CVE-2026-55948

CVE-2026-55948 is a high-severity vulnerability in Microsoft Office Excel, allowing unauthorized attackers to execute code locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. It was published on 2026-07-14T17:17:09.637Z and last modified on 2026-07-16T11:50:22.550Z. This use-after-free issue in Microsoft Office Excel can be exploited by attackers to gain local code execution, pos [truncated]