PatchSiren

Microsoft CVE debriefs · Page 56

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-05-12

CVE-2026-40361

A use-after-free vulnerability in Microsoft Office Word allows local code execution by an unauthorized attacker. The flaw, rated HIGH severity (CVSS 8.4), affects multiple Office versions including Microsoft 365 Apps Enterprise, Office 2019, Office LTSC 2021/2024 (Windows and macOS), and Word 2016. The vulnerability was published on May 12, 2026 and last modified on May 19, 2026. Microsoft has issued a ve [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-40360

CVE-2026-40360 is a high-severity out-of-bounds read vulnerability in Microsoft Office Excel, published by NVD on 2026-05-12 and last modified on 2026-05-19. The vulnerability allows an unauthorized attacker to disclose information locally, with a CVSS 3.1 score of 7.8 (HIGH). The attack vector is local, requiring low attack complexity and no privileges, but does require user interaction. The vulnerabilit [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-40359

A use-after-free vulnerability in Microsoft Office Excel enables local code execution by an unauthorized attacker. The flaw (CWE-416) affects multiple Office deployment channels including Microsoft 365 Apps Enterprise, Office 2016, 2019, and Long Term Servicing Channel versions 2021 and 2024 across Windows (x64/x86) and macOS platforms, as well as Office Online Server prior to version 16.0.10417.20128. Th [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-40358

A use-after-free vulnerability in Microsoft Office allows local code execution by an unauthorized attacker. The flaw was published by NVD on 2026-05-12 and last modified on 2026-05-19. Microsoft has issued a vendor advisory for this vulnerability. Affected products include Microsoft 365 Apps for Enterprise (x64 and x86), Office 2016, Office 2019, and Office Long Term Servicing Channel 2021 and 2024 across [truncated]

MEDIUM Microsoft CVE published 2026-05-12

CVE-2026-35440

CVE-2026-35440 is a medium-severity information disclosure vulnerability in Microsoft Office Word, published on 2026-05-12 and last modified on 2026-05-19. The vulnerability stems from files or directories being accessible to external parties, allowing an unauthorized attacker to disclose information locally. The CVSS 3.1 score of 5.5 reflects local attack vector, low attack complexity, no privileges requ [truncated]

MEDIUM Microsoft CVE published 2026-05-12

CVE-2026-35429

A user interface misrepresentation vulnerability in Microsoft Edge for Android allows network-based attackers to perform spoofing attacks. The vulnerability, classified as CWE-451 (User Interface Misrepresentation of Critical Information), enables an unauthorized attacker to deceive users by presenting misleading interface elements over a network connection. Microsoft has addressed this issue in Edge for [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-34336

CVE-2026-34336 is a high-severity Windows issue in the DWM Core Library that can let an authorized attacker disclose information locally. Microsoft’s advisory and NVD both describe the flaw as a buffer over-read, with NVD mapping it to CWE-126 and a CVSS 3.1 score of 7.8 (HIGH). The exposure is limited to local attack conditions, but the potential impact is serious because confidentiality, integrity, and [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-33841

CVE-2026-33841 is a high-severity vulnerability in the Windows Kernel that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH. It was published on May 12, 2026, and last modified on June 17, 2026. The vulnerability affects various versions of Windows 10, Windows 11, and Windows Server. Microsoft has provided a vendor advisory fo [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-33833

CVE-2026-33833 is a high-severity vulnerability in Azure Machine Learning that allows unauthorized attackers to perform spoofing over a network. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. It was published on May 12, 2026, and last modified on June 18, 2026. The vulnerability is caused by improper neutralization of special elements in output used by a downstream component, allowin [truncated]

CRITICAL Microsoft CVE published 2026-05-12

CVE-2026-33117

Microsoft disclosed CVE-2026-33117 on 2026-05-12. The issue affects Azure SDK for Java and is rated Critical (CVSS 9.1). NVD describes an improper-authentication flaw that could let an unauthorized attacker bypass a security feature over the network. The affected CPE criteria indicate versions before 4.10.6 are vulnerable. Microsoft’s advisory and the NVD record were both updated in the supplied timeline [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-32204

CVE-2026-32204 is a HIGH-severity vulnerability in Azure Monitor Agent that allows an authorized attacker to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and was published on May 12, 2026. It was modified on June 18, 2026. The vulnerability is caused by external control of file name or path. Users of Azure Monitor Agent should review and apply mitigations as recommended by the vendor.

MEDIUM Microsoft CVE published 2026-05-12

CVE-2026-32185

A medium-severity spoofing vulnerability in Microsoft Teams for Android stems from files or directories being accessible to external parties (CWE-552). The vulnerability allows an unauthorized attacker to perform spoofing attacks locally. The attack requires local access (AV:L), low attack complexity (AC:L), no privileges (PR:N), and user interaction (UI:R), with high impact to confidentiality (C:H) but n [truncated]

HIGH Microsoft CVE published 2026-05-12

CVE-2026-32177

CVE-2026-32177 is a high-severity vulnerability in .NET Framework that allows local privilege escalation. The vulnerability is caused by a heap-based buffer overflow and has a CVSS score of 7.3. It was published on May 12, 2026, and modified on June 18, 2026. Affected products include .NET Framework, Visual Studio 2022, and Visual Studio 2026. Microsoft has provided a vendor advisory for mitigation.

MEDIUM Microsoft CVE published 2026-05-12

CVE-2026-32175

A tampering vulnerability exists in .NET Core when handling specially crafted files, allowing attackers to write arbitrary files and directories to certain locations. Users of .NET 10.0, .NET 8.0, .NET 9.0, Visual Studio 2022, and Visual Studio 2026 should apply patches. The security update fixes the vulnerability by ensuring .NET Core properly handles files. This vulnerability has a CVSS score of 4.3 and [truncated]

Known exploited Microsoft CVE published 2026-04-28

CVE-2026-32202

CVE-2026-32202 is a Microsoft Windows vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-04-28. Because it is listed as known exploited, defenders should treat it as a priority remediation item and follow Microsoft’s guidance as well as CISA’s required-action timeline.

HIGH Microsoft CVE published 2026-04-22

CVE-2026-41134

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks. The CVE record was published on 2026-04-22T21:17:09.027Z and has not been modified since then. The NVD entry is currently Modified. This vulnerability allows an attacker to break out of string literals and inject additional co [truncated]

Known exploited Microsoft CVE published 2026-04-22

CVE-2026-33825

CVE-2026-33825 is a Microsoft Defender vulnerability described as an insufficient granularity of access control issue. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-22, which makes it a high-priority item for defenders even though the public source data here does not provide deeper technical detail or a CVSS score. Organizations that use Microsoft Defender should review Mic [truncated]

CRITICAL Microsoft CVE published 2026-04-21

CVE-2026-40372

CVE-2026-40372 is a critical vulnerability in ASP.NET Core that allows an unauthorized attacker to elevate privileges over a network due to improper verification of cryptographic signatures. The vulnerability has a CVSS score of 9.1 and is considered critical. It was published on April 21, 2026, and last modified on June 27, 2026. The vendor, Microsoft, has provided a mitigation or vendor reference for th [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-33116

CVE-2026-33116 is a HIGH severity vulnerability in .NET, .NET Framework, and Visual Studio that allows an unauthorized attacker to deny service over a network. The vulnerability is caused by a loop with an unreachable exit condition, also known as an infinite loop. This vulnerability was published on April 14, 2026, and was modified on June 30, 2026. The CVSS score for this vulnerability is 7.5, indicatin [truncated]

MEDIUM Microsoft CVE published 2026-04-14

CVE-2026-32223

A heap-based buffer overflow vulnerability in the Windows USB Print Driver allows privilege escalation via physical access. The flaw, tracked as CVE-2026-32223, was published on April 14, 2026, and last modified on May 26, 2026. Microsoft has assigned a CVSS 3.1 score of 6.8 (Medium severity), with the attack vector requiring physical access to the target system. The vulnerability affects multiple Windows [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-32203

CVE-2026-32203 is a high-severity stack-based buffer overflow vulnerability in .NET and Visual Studio. An unauthorized attacker could exploit this vulnerability to deny service over a network. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Microsoft is the affected vendor, and .NET and Visual Studio are the impacted products. The CVE was published on April 14, 2026, and last mo [truncated]

MEDIUM Microsoft CVE published 2026-04-14

CVE-2026-32181

A local denial-of-service vulnerability in Microsoft Windows, stemming from improper privilege management in the Connected User Experiences and Telemetry service. An attacker with local, low-privileged access can exploit this flaw to cause service disruption without user interaction. The vulnerability affects multiple Windows 10, Windows 11, and Windows Server versions, with patches available that upgrade [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-32178

CVE-2026-32178 is a high-severity spoofing vulnerability in .NET that allows unauthorized attackers to perform spoofing over a network. The vulnerability has a CVSS score of 7.5 and is considered high severity. Microsoft has released an advisory on this vulnerability. Multiple Red Hat errata have been released to address this vulnerability. The vulnerability affects .NET versions 8.0.0 to 8.0.26, 9.0.0 to [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-32157

CVE-2026-32157 is a high-severity vulnerability in the Remote Desktop Client for Windows Desktop, allowing an unauthorized attacker to execute code over a network. The vulnerability has a CVSS score of 8.8 and is classified as a use-after-free issue. This vulnerability affects systems with Remote Desktop Client exposed to the internet, and defenders should prioritize patching vulnerable systems and verify [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-32154

A use-after-free vulnerability in the Desktop Window Manager (DWM) on Windows allows an authorized attacker to elevate privileges locally. The flaw, rated HIGH severity (CVSS 7.8), was published on April 14, 2026, and last modified on June 1, 2026. Microsoft has addressed this issue through security updates for multiple Windows 11 versions (23H2, 24H2, 25H2, 26H1) and Windows Server editions (2022, 2022 2 [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-32153

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-14T18:17:15.930Z and has not been modified since then. The NVD entry is currently Analyzed. CVE-2026-32153 is a use-after-free vulnerability in Microsoft Windows Speech that allows an authorized attacker to elevate privileges locally. The vulnerability affects multiple Windows versions, including Wi [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-32152

A use-after-free vulnerability in the Desktop Window Manager (DWM) on Windows allows an authorized local attacker to elevate privileges. The flaw was published on 14 April 2026 and last modified on 1 June 2026. Microsoft has issued a security update addressing this vulnerability across multiple Windows 11 versions (23H2, 24H2, 25H2, 26H1) for both x64 and ARM64 architectures, as well as Windows Server 202 [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-32077

CVE-2026-32077 is a HIGH severity (CVSS 7.8) local privilege escalation vulnerability in Microsoft Windows Universal Plug and Play (UPnP) Device Host. The vulnerability stems from an untrusted pointer dereference (CWE-822), allowing an authorized attacker with local access to elevate privileges without user interaction. The attack surface is limited to local exploitation, but successful exploitation grant [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-26174

A race condition vulnerability in Windows Server Update Service allows an authorized attacker to elevate privileges locally. Multiple Windows versions and server releases are affected. This vulnerability requires verification of affected versions and deployment of vendor patches. The vulnerability has a high CVSS score of 7, indicating a significant risk to affected systems. Defenders and administrators s [truncated]

HIGH Microsoft CVE published 2026-04-14

CVE-2026-26151

A spoofing vulnerability in Windows Remote Desktop (RDP) stems from insufficient UI warnings when users initiate potentially dangerous operations. An unauthorized attacker on the network can exploit this to trick users into performing unintended actions. The CVSS 3.1 score of 7.1 (High) reflects network attack vector, low attack complexity, no privileges required, but user interaction needed, with high co [truncated]