Multiple CVEs Disclosed for Microsoft Products with Privilege Escalation Risks
Article Content
- •Multiple CVEs disclosed affecting Microsoft products, with risks of privilege escalation.
- •Attack vectors include malicious Office files and specific protocol settings.
- •Microsoft advises immediate application of security updates to mitigate vulnerabilities.
On September 15, 2026, Microsoft disclosed several vulnerabilities affecting its products, including CVE-2026-55121, CVE-2026-62753, CVE-2026-62721, CVE-2026-49805, CVE-2026-61923, CVE-2026-50683, and CVE-2026-50688. These vulnerabilities include out-of-bounds reads, heap-based buffer overflows, and improper access controls, allowing attackers to elevate privileges to SYSTEM level. The vulnerabilities affect various Microsoft products, including Windows and Microsoft Office. Attack vectors include malicious Office files and specific protocol settings. The vulnerabilities have varying levels of attack complexity, with some requiring user interaction. Microsoft recommends applying security updates as soon as possible to mitigate risks. The CVEs have been assigned CVSS scores indicating potential impacts on confidentiality, integrity, and availability.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (16)
Following this threat?
Track CVE-2026-62721 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft Windows 11 Update Causes Widespread Audio Failures Microsoft's September 2026 Patch Tuesday update introduced critical audio issues affecting USB Audio Class 1.0 devices on Windows 11 versions 24H2 and 25H2. Users reported that audio devices either failed to start or produced no sound, with Device Manager showing error code 10. The update, KB5124008, was part of a…
Critical Elevation of Privilege Vulnerabilities in Windows 11 and 10 Microsoft has released out-of-band security updates for Windows 11 (versions 24H2, 25H2, and 26H1) and Windows 10 (version 1809) to address critical elevation of privilege vulnerabilities. The updates include protections for CVE-2026-62721, a Windows User-Mode Power Service vulnerability published on August 11, 2026…