Skip to main content
← CVE Tracker

Vendor

Microsoft

285 articles

Advertisement

HIGH
Vulnerabilities

CVE-2026-85880: Windows ALPC Heap Overflow Exploited

CISA confirms active exploitation of CVE-2026-85880, a heap-based buffer overflow in Microsoft Windows ALPC leading to local privilege escalation.

Runtime Rebel Intel
4 min read · Sep 8, 2026
CRITICAL
Vulnerabilities

Microsoft KB5122878: Critical Windows 10 ESU/LTSC Security Update

Microsoft's KB5122878 delivers crucial security patches for Windows 10 ESU/LTSC, addressing actively exploited zero-days and 966 vulnerabilities.

Runtime Rebel Intel
4 min read · Sep 8, 2026
HIGH
Threat Intel

BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs

BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.

Runtime Rebel Intel
4 min read · Sep 8, 2026
Microsoft 365 Vishing Leads to Executive Data Theft, Extortion
HIGH
Threat Intel

Microsoft 365 Vishing Leads to Executive Data Theft, Extortion

A widespread threat cluster, PREY-0058, targets Microsoft 365 executives with vishing, AitM token theft, and data extortion.

Runtime Rebel Intel
4 min read · Sep 8, 2026
Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends
HIGH
Threat Intel

Microsoft Teams Abuse, The Gentlemen Ransomware, and PhaaS Trends

Analysis of social engineering campaigns via Microsoft Teams, The Gentlemen ransomware operations, and emerging phishing-as-a-service kits.

Runtime Rebel Intel
3 min read · Sep 4, 2026
Silver Fox Malware Campaign Impersonates Software Vendors
MEDIUM
Malware

Silver Fox Malware Campaign Impersonates Software Vendors

An active Silver Fox malware campaign uses fake software download sites to disable Windows Update and weaken Microsoft Defender defenses.

Runtime Rebel Intel
3 min read · Sep 2, 2026
LOW
Threat Intel

Microsoft Defender Blocks Legitimate Google Search Links

Microsoft Defender for Office 365's Safe Links feature is incorrectly flagging legitimate Google search results as malicious, blocking user access and generating alerts.

Runtime Rebel Intel
4 min read · Sep 2, 2026
HIGH
Vulnerabilities

CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack

Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.

Runtime Rebel Intel
4 min read · Sep 1, 2026
Spring Ring Voice Phishing Targets Microsoft Teams Users
MEDIUM
Threat Intel

Spring Ring Voice Phishing Targets Microsoft Teams Users

Spring Ring is an ongoing vishing campaign leveraging external Microsoft Teams accounts to impersonate IT support for payload delivery and NTLM relay attacks.

Runtime Rebel Intel
4 min read · Sep 1, 2026
Mabna Institute Espionage, BTR.sys Kernel Bypass, & Malware
HIGH
Threat Intel

Mabna Institute Espionage, BTR.sys Kernel Bypass, & Malware

Runtime Rebel details state-sponsored espionage by Mabna Institute, a kernel-level bypass using Microsoft Defender's BTR.sys, and new malware campaigns.

Runtime Rebel Intel
5 min read · Aug 24, 2026
Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated
LOW
Vulnerabilities

Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated

Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.

Runtime Rebel Intel
4 min read · Aug 23, 2026
Weaponizing Defender's BTR.sys to Disable Security Software
MEDIUM
Vulnerabilities

Weaponizing Defender's BTR.sys to Disable Security Software

Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.

Runtime Rebel Intel
4 min read · Aug 22, 2026
HIGH
Malware

SynkLoader Malware Steals Credentials in Microsoft Teams Phishing

New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.

Runtime Rebel Intel
4 min read · Aug 22, 2026
MEDIUM
Threat Intel

Entra Log Analysis: Detecting Password Spray Attacks with PowerShell

Learn to analyze Microsoft Entra sign-in logs using PowerShell to detect password spray attacks and anomalous successful logins from unexpected geographic locations.

Runtime Rebel Intel
4 min read · Aug 21, 2026
INFO
Threat Intel

Auditing Entra ID MFA Gaps with PowerShell and Microsoft Graph

A new PowerShell script helps security teams identify Microsoft Entra ID users not registered for MFA or using weaker authentication methods.

Runtime Rebel Intel
4 min read · Aug 21, 2026
LOW
Vulnerabilities

Microsoft Patch Tuesday: Critical Azure and Entra ID Flaws

Microsoft rolls out 22 new security patches addressing critical elevation of privilege and remote code execution vulnerabilities across Azure and Entra ID.

Runtime Rebel Intel
3 min read · Aug 21, 2026
CoSnitch Attack: Tricking Microsoft Copilot Reveal Architecture
MEDIUM
Threat Intel

CoSnitch Attack: Tricking Microsoft Copilot Reveal Architecture

Researchers reveal the CoSnitch technique that tricks Microsoft Copilot into exposing internal architecture, highlighting AI meta‑hacking risks.

Runtime Rebel Intel
3 min read · Aug 19, 2026
CRITICAL
Vulnerabilities

CVE-2026-33824: Microsoft IKE Double Free RCE Exploit

CISA confirms active exploitation of CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions, enabling remote code execution.

Runtime Rebel Intel
4 min read · Aug 19, 2026
CVE-2026-24301: CoSnitch Exploits Microsoft Copilot Personal
HIGH
Vulnerabilities

CVE-2026-24301: CoSnitch Exploits Microsoft Copilot Personal

Varonis disclosed CoSnitch (CVE-2026-24301), affecting Microsoft Copilot Personal, enabling one-click data exfiltration and persistent memory poisoning.

Runtime Rebel Intel
4 min read · Aug 19, 2026
INFO
Threat Intel

Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics

Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.

Runtime Rebel Intel
2 min read · Aug 18, 2026
SharePoint RCE via CVE-2026-55040 & CVE-2026-63520: Patch Now
HIGH
Vulnerabilities

SharePoint RCE via CVE-2026-55040 & CVE-2026-63520: Patch Now

An AI-assisted exploit chain, leveraging CVE-2026-55040 and CVE-2026-63520, enables unauthenticated RCE on Microsoft SharePoint Server. Immediate patching is critical.

Runtime Rebel Intel
4 min read · Aug 17, 2026
HIGH
Vulnerabilities

ShieldBreak: Windows Zero-Day EoP via Microsoft Defender

Security researcher Nightmare Eclipse released 'ShieldBreak,' a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.

Runtime Rebel Intel
4 min read · Aug 13, 2026
CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC
CRITICAL
Vulnerabilities

CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC

Attackers exploit CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint, leading to data disclosure and modification.

Runtime Rebel Intel
4 min read · Aug 13, 2026
HIGH
Vulnerabilities

CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited

Microsoft addresses 398 vulnerabilities, including an actively exploited privilege escalation flaw in Windows' afd.sys component.

Runtime Rebel Intel
4 min read · Aug 12, 2026