Security News

Current Security Advisories

Concise but actionable advisories on relevant Microsoft, Windows and Active Directory topics: concrete impact, risks and next steps without alarmism.

AD FS: CVE-2026-56155 is under active exploitation

The July Windows Server updates start hardening the AD FS DKM container ACL. CVE-2026-56155 is under active exploitation; administrators should review audit events now and test remediation before October.

AD FSActive DirectoryCVE-2026-56155Windows ServerPatch Management

Active Directory: July updates make Kerberos RC4 enforcement mandatory

With Windows security updates released in or after July 2026, Microsoft removes the audit and rollback phase for CVE-2026-20833. Domain Controllers enforce RC4 hardening; remaining RC4 dependencies can cause authentication failures.

Active DirectoryKerberosWindows ServerMicrosoftPatch Management

Microsoft Entra ID: track CVE-2026-45480 after service mitigation

CVE-2026-45480 affects Azure Active Directory/Microsoft Entra ID and is rated as critical privilege escalation. Microsoft reports completed service-side mitigation; operators should still review privileged tenant changes and evidence limits.

Microsoft Entra IDAzure Active DirectoryIdentity SecurityPrivileged AccessMicrosoft

Windows TCP/IP: prioritize CVE-2026-42904 in LAN-adjacent segments

CVE-2026-42904 affects the Windows TCP/IP stack and can lead to SYSTEM privileges if exploited successfully. Windows clients and servers are in scope; patch evidence and segment boundaries should be reviewed together.

WindowsTCP/IPPatch ManagementEndpoint SecurityMicrosoft

Windows: Close out the BitLocker advisory for CVE-2026-45585

The June 2026 Windows security update includes the fix for CVE-2026-45585. Teams should now document patch level, BitLocker protectors, WinRE state, and recovery key escrow for affected Windows 11 and Windows Server 2025 systems.

WindowsBitLockerWinREEndpoint SecurityMicrosoft

Windows Server/AD: Prioritize CVE-2026-45648 on domain controllers

The June 2026 security updates address a critical remote code execution issue in Active Directory Domain Services. Windows Server 2022 and 2025 domain controllers are in scope; teams should verify patch level, completed reboots, and DC reachability.

Active DirectoryWindows ServerDomain ControllerPatch ManagementMicrosoft

Exchange Online: CVE-2026-48579 mitigated by Microsoft, verify tenant traces

CVE-2026-48579 affects information disclosure in Exchange Online. Microsoft rates the issue highly and has mitigated it in the service; tenant teams should still verify audit logs, permissions and unusual mailbox activity.

Microsoft Exchange OnlineMicrosoft 365Mailbox AuditIdentity SecurityMicrosoft

Microsoft Exchange: verify OWA mitigation for CVE-2026-42897

CVE-2026-42897 affects Outlook Web Access on on-premises Exchange servers and is being exploited. Verify that Exchange Emergency Mitigation Service rule M2.1.x is active and that OWA is not used through Internet Explorer mode.

Microsoft ExchangeOWAWindows ServerPatch ManagementKEVMicrosoft