Skip to main content
Security

Microsoft fixes 974 flaws, including two exploited Windows zero-days

Microsoft fixes 974 flaws, including two exploited Windows zero-days Image: Primary
Microsoft released patches for 974 CVEs across its products, including two Windows zero-days reported as exploited in the wild. One is an ALPC heap-buffer-overflow flaw that can let a local attacker escape a low-privilege AppContainer and gain System privileges; the other affects the Windows Update Stack and also permits local elevation. The release includes 723 Windows flaws and 222 Office bugs. Researchers cited in the report said 20 resolved issues could be wormable, enabling remote code execution without authentication or user interaction.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek, Help Net Security and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Vishing campaign targets executives for Microsoft 365 data theft

Arctic Wolf has described a data-theft and extortion cluster targeting Microsoft 365 and other SaaS accounts through fraudulent IT-help-desk calls, adversary-in-the-middle login pages and residential-proxy session replay. The acti...

Security
Security

N-able issues hotfix for N-central zero-day

N-able released an urgent hotfix for CVE-2026-86218, a critical unauthenticated remote-code-execution vulnerability in its N-central endpoint-management platform. The company said the flaw had been exploited as a zero-day and that...

Security
Security

CISA adds exploited Chromium V8 flaw to KEV catalog

CISA has added CVE-2026-85046, a Chromium V8 type-confusion vulnerability, to its Known Exploited Vulnerabilities catalog, saying it is actively exploited. The flaw can be triggered when a target loads a specially crafted HTML pag...

Security
Security

Natural Resources Wales discloses employee diversity-data exposure

Natural Resources Wales disclosed that a spreadsheet containing equality-monitoring and diversity information for former and current employees was inadvertently published online and later removed. The affected group covers people...