Skip to main content
← CVE Tracker

Vendor

Microsoft

266 articles

VU
CRITICAL
Vulnerabilities

CISA KEV Catalog Update: Microsoft Office RCE and SharePoint Exploited

CISA adds CVE-2009-0238 (Microsoft Office RCE) and CVE-2026-32201 (SharePoint Server input validation) to its Known Exploited Vulnerabilities Catalog.

Runtime Rebel Intel
5 min read · Apr 14, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-30044: SharePoint Server RCE Zero-Day Patched — Patch Now

Microsoft's May 2024 Patch Tuesday addresses 61 vulnerabilities including a critical SharePoint RCE zero-day and a Windows DWM elevation of privilege flaw.

Runtime Rebel Intel
3 min read · Apr 14, 2026
VU
CRITICAL
Vulnerabilities

Windows 10 KB5082200 ESU: Patching April 2026 Zero-Day Flaws

Microsoft addresses two critical zero-days in the Windows 10 KB5082200 Extended Security Update. Learn how to secure EOL systems against active exploitation.

Runtime Rebel Intel
3 min read · Apr 14, 2026
SU
LOW
Supply Chain

Microsoft Windows Hardware Program Fast-Track Reinstatement Guide

Microsoft launches a fast-track process for developers to recover Windows Hardware Program accounts suspended during recent driver-signing security audits.

Runtime Rebel Intel
4 min read · Apr 14, 2026
VU
CRITICAL
Vulnerabilities

CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits

CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…

Runtime Rebel Intel
4 min read · Apr 14, 2026
TH
MEDIUM
Threat Intel

Storm-2755 Targets Canadian Employees in Payroll Pirate Campaigns

Microsoft warns of Storm-2755, a financially motivated threat actor hijacking employee accounts to redirect salary payments via sophisticated phishing.

Runtime Rebel Intel
3 min read · Apr 10, 2026
SU
HIGH
Supply Chain

CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets

Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.

Runtime Rebel Intel
3 min read · Apr 10, 2026
TH
HIGH
Threat Intel

VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins

Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.

Runtime Rebel Intel
4 min read · Apr 10, 2026
CL
MEDIUM
Cloud Security

Federal Evaluators Flag Microsoft Cloud Security Documentation

U.S. federal evaluators expressed a 'lack of confidence' in Microsoft's cloud security posture due to insufficient documentation, despite approval.

Runtime Rebel Intel
5 min read · Apr 9, 2026
SU
MEDIUM
Supply Chain

Microsoft Developer Account Suspensions Block OSS Security Patches

Microsoft's suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.

Runtime Rebel Intel
4 min read · Apr 9, 2026
TH
LOW
Threat Intel

Windows 11 23H2 Start Menu Search Fix — Microsoft Implementation Guide

Microsoft has resolved a Windows 11 23H2 bug causing Start Menu search failures using a Known Issue Rollback. Discover how this fix impacts system stability.

Runtime Rebel Intel
4 min read · Apr 8, 2026
TH
HIGH
Threat Intel

Russian Hackers Exploit Routers to Steal Microsoft Office Tokens

Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…

Runtime Rebel Intel
5 min read · Apr 7, 2026
TH
HIGH
Threat Intel

APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins

Authorities disrupt APT28's FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.

Runtime Rebel Intel
5 min read · Apr 7, 2026
VU
LOW
Vulnerabilities

Fix for Classic Outlook 0x80040115 Error Restores Email Delivery

Microsoft resolves a persistent bug in Classic Outlook causing 0x80040115 errors and email delivery failures for Outlook.com users. Learn how to fix it.

Runtime Rebel Intel
4 min read · Apr 6, 2026
Iran-Linked Password-Spraying Targets 300+ Israeli Organizations
HIGH
Threat Intel

Iran-Linked Password-Spraying Targets 300+ Israeli Organizations

Iran-linked threat actors launched coordinated password-spraying attacks against Israeli and UAE Microsoft 365 environments in March 2026.

Runtime Rebel Intel
3 min read · Apr 6, 2026
SU
HIGH
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read · Apr 5, 2026
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
HIGH
Threat Intel

Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers

Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.

Runtime Rebel Intel
3 min read · Apr 4, 2026
CL
INFO
Cloud Security

Exchange Online Mailbox Access Issues Persist for Outlook Users

Microsoft Exchange Online users on Outlook mobile and macOS are experiencing intermittent mailbox access issues for weeks; investigation ongoing.

Runtime Rebel Intel
4 min read · Apr 3, 2026
TH
INFO
Threat Intel

Windows 11 Version 24H2 Force Upgrade for Unmanaged PCs

Microsoft initiates forced upgrades to Windows 11 24H2 for unmanaged Home and Pro devices to maintain security support and critical update delivery.

Runtime Rebel Intel
3 min read · Apr 3, 2026
TH
INFO
Threat Intel

Classic Outlook Bug Halts Outlook.com Email Delivery for Users

Microsoft is actively investigating a Classic Outlook bug preventing some users from sending emails via Outlook.com. This impacts email delivery and communication.

Runtime Rebel Intel
4 min read · Apr 2, 2026
TH
HIGH
Threat Intel

EvilTokens Fuels Microsoft Device Code Phishing & BEC

New EvilTokens service automates Microsoft device code phishing, enabling account takeover and sophisticated business email compromise (BEC) attacks. Learn how to defend.

Runtime Rebel Intel
5 min read · Apr 1, 2026
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
HIGH
Malware

WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems

Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…

Runtime Rebel Intel
5 min read · Apr 1, 2026
TH
LOW
Threat Intel

Windows 11 KB5086672 Emergency Update Fixes Installation Issues

Microsoft issues emergency update KB5086672 to resolve installation failures and boot loops caused by the KB5079391 non-security preview update.

Runtime Rebel Intel
3 min read · Apr 1, 2026
TH
INFO
Threat Intel

Microsoft Fixes Outlook Classic Crashes Caused by Teams Add-in

Microsoft resolves persistent crashes in Outlook Classic triggered by the Teams Meeting Add-in. Technical details for IT administrators to verify the fix.

Runtime Rebel Intel
3 min read · Mar 31, 2026