Articles from July 15, 2026
Browse all Windows news articles published on July 15, 2026
Microsoft Fixes Windows File Explorer Vulnerability That Leaks Data to Local Attackers—Apply July Updates Now
Microsoft’s July 14, 2026 security patch bundles a fix for CVE-2026-33842, an information‑disclosure bug in Windows File Explorer that could let an attacker who’s already logged on to your PC...
Microsoft Warns of Azure AD Infinite-Loop Flaw Triggered by Unauthenticated Attackers
Microsoft disclosed CVE-2026-50653 on July 14, 2026, an “Important” denial-of-service vulnerability in Azure Active Directory components that anyone can trigger remotely – no account, password,...
Power BI Report Server's XSS Fix Requires a Specific Build—Your Last Update May Not Be Enough
Microsoft has patched an important-rated cross-site scripting vulnerability in Power BI Report Server that could allow an authenticated attacker to inject malicious scripts into the portal. The fix...
Critical SharePoint RCE Patched a Month Ago — Is Your Server Still Exposed?
On July 14, 2026, Microsoft published details of a remote code execution vulnerability in SharePoint Server that needs no authentication, no user interaction, and can be triggered over the network....
Microsoft’s July 2026 Windows Updates Seal a Serious NTFS Security Hole—Patch Now
Microsoft’s monthly security update on July 14, 2026, delivered a fix for a heap-based buffer overflow in the NTFS file system that could allow an attacker to execute arbitrary code on your PC. The...
Patch Microsoft PC Manager Now to Close a Privilege Escalation Hole Windows Update Won’t Touch
Microsoft disclosed a local privilege-escalation vulnerability in its PC Manager application on July 14, 2026. The flaw, tracked as CVE-2026-58636, can allow an attacker who already has a foothold on...
Microsoft Fixes Windows Narrator Flaw That Could Give Attackers System-Level Access
Microsoft’s July 14, 2026 security updates patch a command-injection vulnerability in Windows Narrator that could let a locally authenticated attacker elevate privileges to SYSTEM. Tracked as...
Microsoft Issues Patch for Windows Admin Center Code Execution Flaw — Upgrade to 2.7.4 Now
Microsoft on July 14, 2026, disclosed a vulnerability in Windows Admin Center that could let an attacker with limited access seize control of the entire management gateway. The company rated the flaw...
Microsoft Patches Excel Flaw CVE-2026-58618 That Could Allow Remote Code Execution via Malicious Files
On July 14, 2026, Microsoft rolled out a critical security fix for a vulnerability in Excel that could let attackers take over your computer just by tricking you into opening a booby-trapped...
Microsoft Patches a Critical 8.8-Rated Privilege Hole in Configuration Manager 2509—Here’s Your Urgent Fix Checklist
Microsoft shipped a fix on July 14, 2026 for a network-accessible elevation-of-privilege vulnerability in Configuration Manager 2509 that can give an attacker with minimal domain credentials full...
July’s Windows Update Fixes a Kernel Security Bypass—Here’s Why It Matters
Microsoft’s July 14, 2026 security update patches an important vulnerability in the Windows kernel that could let an attacker bypass a security feature. Tracked as CVE-2026-58614, the flaw requires...
Microsoft's July Patch Tuesday Closes a Critical Media Foundation Gap — Here's What You Must Do
Microsoft on July 14, 2026 pushed out a mammoth set of security updates, rolling up fixes for more than 500 vulnerabilities across its product line. Among them, a bug in Windows Media Foundation...