Skip to content
feed: live
>_ 0dayNews
Vendor

Microsoft

Vulnerabilities and patches across Windows, Exchange Server, Outlook, Active Directory, and Azure — including Patch Tuesday triage and zero-days under active exploitation.

CVEs
CVE-2026-50661
[ MEDIUM ] CVSS 6.1 patched

Windows BitLocker security feature bypass

Publicly disclosed BitLocker Device Encryption bypass fixed in Microsoft's July 2026 Patch Tuesday. Requires physical access; no confirmed exploitation as of publication.

Microsoft / Windows (BitLocker Device Encryption) — see MSRC advisory for affected builds
CVE-2026-55040
[ CRITICAL ] CVSS 9.1 patched

SharePoint Server JWT token authentication bypass

Critical authentication bypass in Microsoft SharePoint Server's JWT validation pipeline. Half of a pre-auth RCE chain disclosed by Rapid7; patched in the July 2026 cumulative update.

Microsoft / Microsoft SharePoint Server (on-prem; see MSRC advisory for affected builds)
CVE-2026-56155
[ HIGH ] CVSS 7.8 kev

AD FS elevation of privilege — insufficient access-control granularity

Active Directory Federation Services access-control granularity flaw lets an authorized attacker escalate privileges locally. Exploited in the wild; added to CISA KEV 2026-07-14.

Microsoft / Active Directory Federation Services (AD FS) — see MSRC advisory for affected builds
CVE-2026-56164
[ MEDIUM ] CVSS 5.3 kev

SharePoint Server elevation of privilege — missing authentication for critical function

SharePoint Server ships a critical function that's reachable without authentication, letting an unauthenticated attacker escalate over a network. Exploited in the wild; added to CISA KEV 2026-07-14.

Microsoft / Microsoft SharePoint Server (see MSRC advisory for affected builds)
CVE-2026-58644
[ CRITICAL ] CVSS 9.8 kev

Microsoft SharePoint deserialization of untrusted data (unauth RCE)

A critical unauthenticated deserialization RCE in on-prem Microsoft Office SharePoint (CVE-2026-58644, CVSS 9.8). Patched July 14 in Microsoft's July 2026 updates; added to CISA KEV on July 16.

Microsoft / SharePoint Server 2016 / 2019 / Subscription Edition
CVE-2026-50656
[ HIGH ] CVSS 7.8 patched

Microsoft Defender Malware Protection Engine race-condition EoP ('RoguePlanet')

Race-condition EoP in the Microsoft Malware Protection Engine (Defender) that lets a local user reach SYSTEM. Fixed in engine build 1.1.26060.3008. Public PoC.

Microsoft / Microsoft Malware Protection Engine (versions 1.1.0.0 through 1.1.26060.3008 — shipped with Microsoft Defender on Windows 10, Windows 11, Windows Server, and Microsoft Defender for Endpoint on Server)
CVE-2026-45659
[ HIGH ] CVSS 8.8 EPSS 3.2% kev

Microsoft SharePoint Server deserialization remote code execution

A high-severity deserialization-of-untrusted-data flaw in on-premises Microsoft SharePoint Server that leads to remote code execution. Patched by Microsoft in the May 2026 security update; added to the CISA Known Exploited Vulnerabilities catalog on July 2, 2026 after confirmed exploitation in the wild.

Microsoft / SharePoint Server (on-premises)
CVE-2026-32201
[ MEDIUM ] CVSS 6.5 kev

SharePoint Server spoofing via improper input validation

Network-reachable spoofing flaw in on-premises Microsoft SharePoint Server (Enterprise 2016, Server 2019, Subscription Edition). Patched by Microsoft in April 2026; on CISA KEV since 2026-04-14.

Microsoft / Microsoft SharePoint Server (Enterprise 2016, Server 2019, Subscription Edition)
CVE-2026-33825
[ HIGH ] CVSS 7.8 EPSS 6.7% kev

Microsoft Defender Antimalware Platform Local Privilege Escalation (BlueHammer)

A local privilege escalation flaw in Microsoft Defender Antimalware Platform caused by insufficient access-control granularity. An authorized local attacker can elevate privileges. Patched in April 2026 Patch Tuesday, added to the CISA KEV catalog on 2026-04-22, and confirmed by CISA in July 2026 as weaponized in ransomware attacks. Disclosed as a zero-day by researcher "Chaotic Eclipse" (aka Nightmare-Eclipse) alongside two sibling flaws — RedSun and UnDefend — as a protest of Microsoft's disclosure coordination.

Microsoft / Defender Antimalware Platform (versions 4.0.0.0 through before 4.18.26030.3011)
CVE-2024-21413
[ CRITICAL ] CVSS 9.8 EPSS 94.7% kev

Microsoft Outlook MonikerLink Remote Code Execution

A vulnerability in how Microsoft Outlook processes specially crafted hyperlinks (the "MonikerLink" flaw) allows an attacker to bypass Outlook's Protected View and trigger remote code execution simply by having a user click a malicious link in an email.

Microsoft / Outlook (Microsoft 365 Apps, Office 2016–2021)
CVE-2022-30190
[ HIGH ] CVSS 7.8 EPSS 99.4% kev

Follina — Microsoft Windows Support Diagnostic Tool Remote Code Execution

A remote-code-execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) allows an attacker to execute arbitrary code when a malicious Office document is opened — triggered via a remote template reference that invokes MSDT through the ms-msdt URI scheme, without requiring macros.

Microsoft / Windows Support Diagnostic Tool (MSDT)
CVE-2021-40444
[ HIGH ] CVSS 8.8 EPSS 96.8% kev

MSHTML Remote Code Execution via Malicious Office Document

A remote-code-execution vulnerability in the MSHTML (Trident) browser engine component used by Microsoft Office allows an attacker to execute arbitrary code when a victim opens a specially crafted Office document — exploited in the wild as a zero-day before Microsoft's patch shipped.

Microsoft / Windows MSHTML
CVE-2021-34527
[ HIGH ] CVSS 8.8 EPSS 99.8% kev

PrintNightmare — Windows Print Spooler Remote Code Execution

A remote-code-execution vulnerability in the Windows Print Spooler service allows an authenticated attacker to run arbitrary code with SYSTEM privileges, or a domain-authenticated attacker to compromise a domain controller, by abusing the spooler's remote printer-driver installation functionality.

Microsoft / Windows Print Spooler
CVE-2021-26855
[ CRITICAL ] CVSS 9.8 EPSS 100.0% kev

ProxyLogon — Microsoft Exchange Server Server-Side Request Forgery

A server-side request forgery vulnerability in Microsoft Exchange Server allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange server. Chained with three additional Exchange vulnerabilities (CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) it delivers full pre-authentication remote code execution — the "ProxyLogon" chain exploited at mass scale in early 2021.

Microsoft / Exchange Server
Articles
~/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup
WSUS sync fix only for new installs, old servers still stuck
microsoft

WSUS sync fix only for new installs, old servers still stuck

WSUS servers on Windows Server 2012+ have failed to sync since roughly July 13. Microsoft's July 18 mitigation restores fresh installs; older ones wait on a metadata cleanup step.

read →
~/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix
Microsoft ships KB5121767 OOB for Dell IPF driver hold
microsoft

Microsoft ships KB5121767 OOB for Dell IPF driver hold

Microsoft shipped KB5121767 on 2026-07-20 to patch the Intel IPF driver incompatibility stranding a subset of Dell PCs off July's Windows 11 security update.

read →
~/articles/2026-07-19-legacyhive-nightmare-eclipse-windows-user-profile-usrclass-lpe-unpatched
LegacyHive: PoC drops for unpatched Windows LPE zero-day
microsoft

LegacyHive: PoC drops for unpatched Windows LPE zero-day

A researcher publishing as "Nightmare Eclipse" dropped a PoC for LegacyHive — an unpatched local privilege escalation in Windows' User Profile Service.

read →
~/articles/2026-07-17-nightmare-eclipse-legacyhive-windows-user-profile-service-lpe-zero-day
LegacyHive: unpatched Windows LPE zero-day, PoC public
microsoft

LegacyHive: unpatched Windows LPE zero-day, PoC public

Researcher Nightmare Eclipse dropped LegacyHive — an unpatched Windows User Profile Service LPE — hours after July Patch Tuesday. No CVE, PoC on GitHub.

read →
~/articles/2026-07-17-microsoft-windows-server-2022-mainstream-eos-october-13-extended-2031
Windows Server 2022 mainstream support ends Oct 13
microsoft

Windows Server 2022 mainstream support ends Oct 13

Microsoft's Windows Server 2022 leaves mainstream support October 13, 2026 — but extended support runs five more years with security updates at no extra cost.

read →
~/articles/2026-07-16-microsoft-windows-11-24h2-home-pro-eos-october-13-25h2-enablement
Windows 11 24H2 Home and Pro: 90 days to end of updates
microsoft

Windows 11 24H2 Home and Pro: 90 days to end of updates

Microsoft has set October 13, 2026 as the last patch day for Windows 11 24H2 Home and Pro. Enterprise and Education get one more year — the usual split.

read →
~/articles/2026-07-16-cisa-kev-sharepoint-cve-2026-58644-deserialization-fourth-in-week
CISA adds a fourth SharePoint bug to KEV in 48 hours
microsoft

CISA adds a fourth SharePoint bug to KEV in 48 hours

CVE-2026-58644 — an unauthenticated deserialization RCE, CVSS 9.8 — landed on CISA KEV this morning, two days after Microsoft shipped the SharePoint fix.

read →
~/articles/2026-07-16-microsoft-mdash-july-622-cves-ai-attribution-krebs-rapid7
The July patch count Microsoft warned would come
Analysis
microsoft

The July patch count Microsoft warned would come

Microsoft credited AI discovery for July's record 622-CVE Patch Tuesday. That's the second half of the story the MDASH post previewed a week earlier.

read →
~/articles/2026-07-16-microsoft-kb5099539-windows-10-esu-july-22h2-ltsc-2021
KB5099539 lands: Windows 10 ESU carries the July zero-days
microsoft

KB5099539 lands: Windows 10 ESU carries the July zero-days

Microsoft's KB5099539 delivers July's Patch Tuesday to Windows 10 22H2 and LTSC 2021 fleets, including two exploited zero-days. Enrollment required.

read →
~/articles/2026-07-15-chaotic-eclipse-legacyhive-profsvc-lpe-poc-drop
LegacyHive: Chaotic Eclipse's fourth Windows zero-day
microsoft

LegacyHive: Chaotic Eclipse's fourth Windows zero-day

Researcher 'Chaotic Eclipse' released LegacyHive, a Windows User Profile Service arbitrary-hive-load LPE PoC, hours after July Patch Tuesday. Unpatched.

read →
~/articles/2026-07-15-cisa-sharepoint-three-cves-bod-26-04-july-17-deadline
CISA: three SharePoint bugs exploited, patch by July 17
microsoft

CISA: three SharePoint bugs exploited, patch by July 17

CISA named three actively exploited on-prem SharePoint CVEs and put a July 17 remediation clock on federal agencies. Shadowserver counts 800+ unpatched servers. Patch on one maintenance touch.

read →
~/articles/2026-07-15-microsoft-safeguard-hold-dell-kb5101650-intel-ipf-shutdowns
Microsoft blocks Dell PCs from July KB5101650 rollout
microsoft

Microsoft blocks Dell PCs from July KB5101650 rollout

Microsoft applied a safeguard hold on July's KB5101650 for a limited set of Dell devices running Windows 11 25H2 and 24H2 after a June preview update triggered Intel IPF driver crashes, heat, and battery drain.

read →
~/articles/2026-07-15-microsoft-entra-id-passkeys-default-september-sms-voice-retirement-feb-2027
Entra ID passkeys go default in Sept; SMS/voice out Feb 1
microsoft

Entra ID passkeys go default in Sept; SMS/voice out Feb 1

Microsoft is auto-enrolling Entra ID SMS/voice MFA users into passkeys starting September 2026 and retiring native SMS/voice delivery on Feb 1, 2027. What to do.

read →
~/articles/2026-07-14-rapid7-sharepoint-cve-2026-55040-jwt-auth-bypass-rce-chain-half
SharePoint JWT bypass fixed; RCE half of chain still open
microsoft

SharePoint JWT bypass fixed; RCE half of chain still open

Rapid7 disclosed CVE-2026-55040 today — a SharePoint JWT auth bypass patched in July Patch Tuesday. Second half of a pre-auth RCE chain lands next month. Patch now.

read →
~/articles/2026-07-14-microsoft-july-patch-tuesday-570-cves-adfs-sharepoint-bitlocker-zero-days
Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out
microsoft

Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out

Microsoft's July 2026 Patch Tuesday ships 570 CVEs, including two exploited zero-days in AD FS and SharePoint plus a publicly disclosed BitLocker bypass. Patch AD FS first.

read →
~/articles/2026-07-14-proofpoint-oauth-client-id-spoofing-entra-signin-logs-blind
OAuth client ID spoofing sneaks past Entra sign-in logs
microsoft

OAuth client ID spoofing sneaks past Entra sign-in logs

Proofpoint tracked two credential-stuffing crews that submit fake OAuth application IDs to Entra ID's token endpoint. The sign-in logs don't record what defenders are looking for.

read →
~/articles/2026-07-14-eset-uefi-shim-cve-2026-8863-secure-boot-bypass
ESET: 11 old signed UEFI shims still bypass Secure Boot
microsoft

ESET: 11 old signed UEFI shims still bypass Secure Boot

ESET's Martin Smolár found 11 old Microsoft-signed UEFI shims that still bypass Secure Boot — CVE-2026-8863, revoked via the June DBX update.

read →
~/articles/2026-07-10-microsoft-mdash-msrc-humans-downstream
Microsoft's MDASH and the humans downstream of it
Analysis
microsoft

Microsoft's MDASH and the humans downstream of it

Microsoft says AI-found Windows bugs will make Patch Tuesdays bigger. The interesting part isn't the AI — it's the human queue that signs off on what ships.

read →
~/articles/2026-07-09-microsoft-mdash-ai-scanner-fatter-patch-tuesdays
Microsoft: MDASH will grow Patch Tuesday numbers
Analysis
microsoft

Microsoft: MDASH will grow Patch Tuesday numbers

Microsoft EVP Pavan Davuluri says a multi-model AI scanner called MDASH will surface more Windows bugs — expect higher-volume monthly releases.

read →
~/articles/2026-07-09-forg365-phaas-m365-aitm-device-code-zerobec
Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
microsoft

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365

ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

read →
~/articles/2026-07-09-microsoft-owa-light-retirement-exchange-server
Microsoft to retire OWA Light in Exchange Server
Analysis
microsoft

Microsoft to retire OWA Light in Exchange Server

Microsoft is disabling OWA Light in an August 2026 Exchange Server update, ending a legacy client shipped when IE6 was current. Admins can disable it today.

read →
~/articles/2026-07-09-microsoft-defender-rogueplanet-cve-2026-50656-lpe-patch
Microsoft patches Defender 'RoguePlanet' LPE; PoC public
microsoft

Microsoft patches Defender 'RoguePlanet' LPE; PoC public

Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

read →
~/articles/2026-07-08-pink-o-unc-066-entra-passkey-vishing-okta-unit42
Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants
microsoft

Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants

Okta and Unit 42 attribute an ongoing vishing campaign — active since April — that walks Microsoft 365 users through enrolling a passkey the attacker controls.

read →
~/articles/2026-07-08-debull-m365-device-code-phishing-storm-2372-overlap
DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372
microsoft

DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372

ZeroBEC reports DEBULL — a device-code phishing kit repackaging Storm-2372 tradecraft — active against M365 tenants late June to early July. Block it.

read →
~/articles/2026-07-04-bluehammer-defender-lpe-kev-ransomware-confirmed
BlueHammer Defender LPE Now Used in Ransomware
microsoft

BlueHammer Defender LPE Now Used in Ransomware

CVE-2026-33825, the Microsoft Defender local privilege escalation disclosed as a zero-day by 'Chaotic Eclipse' in April, is confirmed weaponized in ransomware. Patched. Ransomware family unnamed.

read →
~/articles/2026-07-03-sharepoint-cve-2026-45659-kev-active-exploitation
SharePoint RCE now on CISA KEV: patch it this week, not next
microsoft

SharePoint RCE now on CISA KEV: patch it this week, not next

CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.

read →
~/articles/2026-07-02-follina-msdt-zero-day-explained
Follina: The MSDT Bug That Skipped Macro Warnings
Explainer
microsoft

Follina: The MSDT Bug That Skipped Macro Warnings

CVE-2022-30190 let a Word document trigger arbitrary code execution through the Windows Support Diagnostic Tool — no macros, and in some configurations no explicit click required beyond opening the file.

read →
~/articles/2026-07-01-mshtml-office-zero-day-cve-2021-40444
The MSHTML Zero-Day That Weaponized a Word Doc
Explainer
microsoft

The MSHTML Zero-Day That Weaponized a Word Doc

CVE-2021-40444 let attackers execute arbitrary code through a malicious Office document with no macros required — exploited in the wild before Microsoft's patch existed.

read →
~/articles/2026-07-01-proxylogon-exchange-server-attack-chain
ProxyLogon: Inside the Exchange Server Attack Chain
Analysis
microsoft

ProxyLogon: Inside the Exchange Server Attack Chain

CVE-2021-26855 and three chained Exchange Server bugs gave attackers unauthenticated remote code execution — and led to a compromise event so widespread the FBI obtained a court order to remove webshells itself.

read →
~/articles/2026-06-30-printnightmare-windows-print-spooler-explained
PrintNightmare: A Leaked PoC Forced an Emergency Patch
Explainer
microsoft

PrintNightmare: A Leaked PoC Forced an Emergency Patch

CVE-2021-34527 let attackers turn the Windows Print Spooler service — running by default on nearly every Windows machine — into a path to SYSTEM privileges or full domain compromise.

read →
~/articles/2026-06-28-outlook-monikerlink-rce-patch-tuesday-explainer
Outlook MonikerLink Bug Bypasses Protected View
Explainer
microsoft

Outlook MonikerLink Bug Bypasses Protected View

CVE-2024-21413 let attackers bypass Outlook's Protected View sandbox with a single specially crafted hyperlink, leading to code execution and potential credential leakage. Patched in February 2024's Patch Tuesday.

read →