Security Advisories

Current risks, placed in context.

Concise analysis of relevant vulnerabilities and changes: what is affected, how serious is the risk and what should responsible teams review now?

Windows Update Stack: CVE-2026-81963 actively exploited

CVE-2026-81963 allows local SYSTEM privileges on Windows 11 and Windows Server 2025. Prioritize September updates, complete restarts and verify patch status.

MicrosoftWindows 11Windows Server 2025CVE-2026-81963Privilege EscalationPatch Management

Teams support scam: attack path into Active Directory

Microsoft has observed a campaign using fake IT support contacts over Teams. Remote access, a silent MSI installation and WinRM lead toward domain controllers and certificate authorities.

MicrosoftMicrosoft TeamsActive DirectorySocial EngineeringWinRMIncident ResponseRemote Support

Windows IKE: CISA prioritizes CVE-2026-33824

CISA has added the critical Windows IKEv2 flaw CVE-2026-33824 to the KEV catalog. Update systems and restrict UDP 500/4500 to required peers.

MicrosoftWindowsCVE-2026-33824IKEv2IPsecRemote Code ExecutionPatch Management

Windows: CVE-2026-68820 actively exploited

Microsoft has fixed an actively exploited use-after-free flaw in the Windows Ancillary Function Driver for WinSock. Prioritize the August updates across clients and servers.

MicrosoftWindowsCVE-2026-68820WinSockPrivilege EscalationPatch Management

SharePoint: CVE-2026-56164 actively exploited

Microsoft lists CVE-2026-56164 in on-premises SharePoint farms as actively exploited. Apply the July patches and migrate SharePoint 2016 and 2019.

MicrosoftSharePoint ServerCVE-2026-56164Active ExploitationPatch ManagementAMSI

Windows RDP files: enforce SHA-256 trust with Group Policy

The July 2026 Windows security updates add SHA-2 thumbprints for signed RDP file trust. Organizations should block unknown publishers, sign their own RDP files, and retire existing SHA-1 pins.

WindowsRemote DesktopRDPGroup PolicySHA-256Phishing Protection

AD FS: CVE-2026-56155 is under active exploitation

The July Windows Server updates start hardening the AD FS DKM container ACL. CVE-2026-56155 is under active exploitation; administrators should review audit events now and test remediation before October.

AD FSActive DirectoryCVE-2026-56155Windows ServerPatch Management

Active Directory: July updates make Kerberos RC4 enforcement mandatory

With Windows security updates released in or after July 2026, Microsoft removes the audit and rollback phase for CVE-2026-20833. Domain Controllers enforce RC4 hardening; remaining RC4 dependencies can cause authentication failures.

Active DirectoryKerberosWindows ServerMicrosoftPatch Management

Microsoft Entra ID: track CVE-2026-45480 after service mitigation

CVE-2026-45480 affects Azure Active Directory/Microsoft Entra ID and is rated as critical privilege escalation. Microsoft reports completed service-side mitigation; operators should still review privileged tenant changes and evidence limits.

Microsoft Entra IDAzure Active DirectoryIdentity SecurityPrivileged AccessMicrosoft

Windows TCP/IP: prioritize CVE-2026-42904 in LAN-adjacent segments

CVE-2026-42904 affects the Windows TCP/IP stack and can lead to SYSTEM privileges if exploited successfully. Windows clients and servers are in scope; patch evidence and segment boundaries should be reviewed together.

WindowsTCP/IPPatch ManagementEndpoint SecurityMicrosoft

Windows: Close out the BitLocker advisory for CVE-2026-45585

The June 2026 Windows security update includes the fix for CVE-2026-45585. Teams should now document patch level, BitLocker protectors, WinRE state, and recovery key escrow for affected Windows 11 and Windows Server 2025 systems.

WindowsBitLockerWinREEndpoint SecurityMicrosoft

Windows Server/AD: Prioritize CVE-2026-45648 on domain controllers

The June 2026 security updates address a critical remote code execution issue in Active Directory Domain Services. Windows Server 2022 and 2025 domain controllers are in scope; teams should verify patch level, completed reboots, and DC reachability.

Active DirectoryWindows ServerDomain ControllerPatch ManagementMicrosoft

Exchange Online: CVE-2026-48579 mitigated by Microsoft, verify tenant traces

CVE-2026-48579 affects information disclosure in Exchange Online. Microsoft rates the issue highly and has mitigated it in the service; tenant teams should still verify audit logs, permissions and unusual mailbox activity.

Microsoft Exchange OnlineMicrosoft 365Mailbox AuditIdentity SecurityMicrosoft

Microsoft Exchange: verify OWA mitigation for CVE-2026-42897

CVE-2026-42897 affects Outlook Web Access on on-premises Exchange servers and is being exploited. Verify that Exchange Emergency Mitigation Service rule M2.1.x is active and that OWA is not used through Internet Explorer mode.

Microsoft ExchangeOWAWindows ServerPatch ManagementKEVMicrosoft