Skip to main content
← CVE Tracker

Vendor

Microsoft

266 articles

Microsoft Defender Binaries Exploited as Attack Tools
MEDIUM
Threat Intel

Microsoft Defender Binaries Exploited as Attack Tools

Security researchers have identified methods to subvert Microsoft Defender binaries for malicious code execution and EDR bypass. Learn how to defend.

Runtime Rebel Intel
3 min read · Apr 22, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-38094: 1,300+ SharePoint Servers At Risk of RCE

Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2024-38094, a critical RCE vulnerability actively exploited by threat actors.

Runtime Rebel Intel
3 min read · Apr 22, 2026
VU
HIGH
Vulnerabilities

CVE-2023-38171: ASP.NET Core Privilege Escalation — Mitigation Guide

Microsoft issues emergency OOB security updates for a critical ASP.NET Core privilege escalation flaw. Learn how to patch affected systems now.

Runtime Rebel Intel
3 min read · Apr 22, 2026
TH
HIGH
Threat Intel

Microsoft Teams Abused in Helpdesk Impersonation Attacks: TTPs & Mitigations

Microsoft warns of helpdesk impersonation attacks via Teams external collaboration.

Runtime Rebel Intel
4 min read · Apr 20, 2026
VU
MEDIUM
Vulnerabilities

Microsoft Releases OOB Updates to Fix Windows Server Boot Issues

Microsoft issues emergency out-of-band updates to resolve critical authentication failures and boot loops caused by the April 2026 security patches.

Runtime Rebel Intel
4 min read · Apr 20, 2026
VU
HIGH
Vulnerabilities

Android Dirty Stream Path Traversal: Detecting and Patching App Exploits

Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.

Runtime Rebel Intel
4 min read · Apr 20, 2026
VU
LOW
Vulnerabilities

Edge Update Breaks Microsoft Teams Right-Click Paste Functionality

A recent Microsoft Edge browser update has disabled the right-click paste feature in the Microsoft Teams desktop client, impacting global user productivity.

Runtime Rebel Intel
3 min read · Apr 18, 2026
Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited
CRITICAL
Vulnerabilities

Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited

Huntress warns of active exploitation of three Microsoft Defender vulnerabilities, including BlueHammer and RedSun, allowing for privilege escalation.

Runtime Rebel Intel
4 min read · Apr 17, 2026
VU
HIGH
Vulnerabilities

Windows Server Domain Controllers Hit by LSASS Reboot Loops

Microsoft confirms LSASS crashes causing persistent reboot loops on Windows Server Domain Controllers following the April 2024 security update cycle.

Runtime Rebel Intel
4 min read · Apr 17, 2026
Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation
HIGH
Threat Intel

Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation

Analysis of recent threats including a Microsoft Defender zero-day, SonicWall brute-force campaigns, and critical RCE in legacy Microsoft Excel components.

Runtime Rebel Intel
4 min read · Apr 16, 2026
VU
LOW
Vulnerabilities

Windows Server 2025 KB5082063 Update Fails to Install — Analysis

Microsoft is investigating reports of KB5082063 failing to install on Windows Server 2025, leaving systems potentially vulnerable to unpatched threats.

Runtime Rebel Intel
4 min read · Apr 16, 2026
Big Tech Compliance Failures in CA Privacy Law Opt-Out Requests
MEDIUM
Compliance

Big Tech Compliance Failures in CA Privacy Law Opt-Out Requests

An audit reveals Google, Meta, and Microsoft frequently ignore California privacy law opt-out requests, posing significant compliance and data privacy risks.

Runtime Rebel Intel
4 min read · Apr 15, 2026
VU
HIGH
Vulnerabilities

Microsoft Awards $2.3M for Cloud and AI Vulnerabilities at Zero Day Quest

Microsoft pays $2.3 million for nearly 700 vulnerability submissions targeting Azure, Microsoft 365, and AI services during the Zero Day Quest event.

Runtime Rebel Intel
4 min read · Apr 15, 2026
SAP CVE-2026-27681: Critical SQL Injection Vulnerability Patch Guidance
HIGH
Vulnerabilities

SAP CVE-2026-27681: Critical SQL Injection Vulnerability Patch Guidance

April Patch Tuesday addresses a critical 9.9 CVSS SQL injection vulnerability in SAP Business Warehouse and updates for Microsoft, Adobe, and Fortinet.

Runtime Rebel Intel
3 min read · Apr 15, 2026
Microsoft and Salesforce Patch Prompt Injection Flaws in AI Agents
HIGH
Cloud Security

Microsoft and Salesforce Patch Prompt Injection Flaws in AI Agents

Researchers identified prompt injection vulnerabilities in Microsoft Copilot and Salesforce Agentforce that could allow attackers to exfiltrate sensitive data.

Runtime Rebel Intel
3 min read · Apr 15, 2026
TH
MEDIUM
Threat Intel

Microsoft Resolves Windows Server 2025 Automatic Upgrade Bug

Microsoft has addressed a critical deployment bug where Windows Server 2019 and 2022 systems were unexpectedly upgraded to Windows Server 2025 via KB5044284.

Runtime Rebel Intel
4 min read · Apr 15, 2026
VU
MEDIUM
Vulnerabilities

Windows Update Triggers BitLocker Recovery: Mitigation and Analysis

Microsoft confirms April security updates cause unexpected BitLocker recovery prompts on Windows Servers. Learn how to resolve the boot issues and recover keys.

Runtime Rebel Intel
3 min read · Apr 15, 2026
SharePoint Zero-Day Fixed in Microsoft April 2026 Security Updates
CRITICAL
Vulnerabilities

SharePoint Zero-Day Fixed in Microsoft April 2026 Security Updates

Microsoft addresses 169 vulnerabilities, including an actively exploited SharePoint zero-day. Learn how to secure your environment against these flaws.

Runtime Rebel Intel
3 min read · Apr 15, 2026
VU
CRITICAL
Vulnerabilities

Microsoft April 2026 Patch Tuesday: 164 CVEs and Two Zero-Days

Microsoft's April 2026 Patch Tuesday addresses 164 vulnerabilities, including two exploited zero-days and eight critical RCE flaws. Read our technical analysis.

Runtime Rebel Intel
4 min read · Apr 15, 2026
Microsoft $10B Investment: Advancing Japan's AI and Cybersecurity
INFO
Cloud Security

Microsoft $10B Investment: Advancing Japan's AI and Cybersecurity

Microsoft commits $10 billion to Japan for AI infrastructure and cybersecurity, focusing on sovereign AI requirements and national digital resilience.

Runtime Rebel Intel
4 min read · Apr 15, 2026
Microsoft Patch Update: Zero-Day Privilege Elevation Dominates
HIGH
Vulnerabilities

Microsoft Patch Update: Zero-Day Privilege Elevation Dominates

Microsoft's latest patch update addresses 165 vulnerabilities, with over half being privilege elevation flaws, including two actively exploited zero-days.

Runtime Rebel Intel
4 min read · Apr 15, 2026
VU
CRITICAL
Vulnerabilities

April 2026 Patch Tuesday: SharePoint Zero-Day, BlueHammer, & Adobe RCE

Microsoft's April 2026 Patch Tuesday addresses 167 vulnerabilities, including a SharePoint Server zero-day, Windows Defender 'BlueHammer' flaw, and an actively exploited…

Runtime Rebel Intel
5 min read · Apr 15, 2026
TH
MEDIUM
Threat Intel

Windows Hardening: New Protections for Malicious RDP Files

Microsoft introduces enhanced security measures for Windows to mitigate risks from malicious .rdp files used in credential harvesting and data exfiltration.

Runtime Rebel Intel
4 min read · Apr 15, 2026
VU
MEDIUM
Vulnerabilities

Microsoft Patch Tuesday April 2026: Record Update Cycle Analysis

Analysis of Microsoft's April 2026 Patch Tuesday, highlighted as a record release, providing context and recommendations for security professionals.

Runtime Rebel Intel
4 min read · Apr 14, 2026