Security News

Current Security Advisories

Concise but actionable advisories on relevant Microsoft, Windows and Active Directory topics: concrete impact, risks and next steps without alarmism.

Windows Server/AD: Prioritize CVE-2026-45648 on domain controllers

The June 2026 security updates address a critical remote code execution issue in Active Directory Domain Services. Windows Server 2022 and 2025 domain controllers are in scope; teams should verify patch level, completed reboots, and DC reachability.

Active DirectoryWindows ServerDomain ControllerPatch ManagementMicrosoft

Exchange Online: CVE-2026-48579 mitigated by Microsoft, verify tenant traces

CVE-2026-48579 affects information disclosure in Exchange Online. Microsoft rates the issue highly and has mitigated it in the service; tenant teams should still verify audit logs, permissions and unusual mailbox activity.

Microsoft Exchange OnlineMicrosoft 365Mailbox AuditIdentity SecurityMicrosoft

Microsoft Exchange: verify OWA mitigation for CVE-2026-42897

CVE-2026-42897 affects Outlook Web Access on on-premises Exchange servers and is being exploited. Verify that Exchange Emergency Mitigation Service rule M2.1.x is active and that OWA is not used through Internet Explorer mode.

Microsoft ExchangeOWAWindows ServerPatch ManagementKEVMicrosoft