Live
Microsoft Warns of Azure AD Infinite-Loop Flaw Triggered by Unauthenticated Attackers·MSFT +2.1%Power BI Report Server's XSS Fix Requires a Specific Build—Your Last Update May Not Be Enough·NVDA +0.2%CVE-2026-57097: Microsoft Confirms XML Security Bypass, but Details Are Scarce·GOOGL +1.7%CVE-2026-56185: Your Windows Admin Center Is Likely Vulnerable — Here’s the Fix That Windows Update Misses·AMZN +1.1%Microsoft Fixes Network-Elevation Flaw in Windows Admin Center – Patch Now·MSFT +2.1%CVE-2026-55006: Patch Now to Stop Low-Privileged Users from Hijacking Your Exchange Server·NVDA +0.2%Microsoft's 570-Fix Patch Tuesday: Two Zero-Days Exploited, BitLocker Bypass Disclosed·GOOGL +1.7%Windows 11 July Update Lets You Pause Updates Forever—Here’s How the New Calendar Works·AMZN +1.1%Microsoft Warns of Azure AD Infinite-Loop Flaw Triggered by Unauthenticated Attackers·MSFT +2.1%Power BI Report Server's XSS Fix Requires a Specific Build—Your Last Update May Not Be Enough·NVDA +0.2%CVE-2026-57097: Microsoft Confirms XML Security Bypass, but Details Are Scarce·GOOGL +1.7%CVE-2026-56185: Your Windows Admin Center Is Likely Vulnerable — Here’s the Fix That Windows Update Misses·AMZN +1.1%Microsoft Fixes Network-Elevation Flaw in Windows Admin Center – Patch Now·MSFT +2.1%CVE-2026-55006: Patch Now to Stop Low-Privileged Users from Hijacking Your Exchange Server·NVDA +0.2%Microsoft's 570-Fix Patch Tuesday: Two Zero-Days Exploited, BitLocker Bypass Disclosed·GOOGL +1.7%Windows 11 July Update Lets You Pause Updates Forever—Here’s How the New Calendar Works·AMZN +1.1%

Microsoft Security

The latest Microsoft Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 8:02 PM
Latest Most Read Breaking
Sort
Azure Active Directory · Denial Of Service

Microsoft Warns of Azure AD Infinite-Loop Flaw Triggered by Unauthenticated Attackers

Microsoft disclosed CVE-2026-50653 on July 14, 2026, an “Important” denial-of-service vulnerability in Azure Active Directory components that anyone can trigger remotely – no account, password,...

Advertisement
Cve 2026 56169 · Microsoft Security

Microsoft Fixes Network-Elevation Flaw in Windows Admin Center – Patch Now

Microsoft has patched a high-severity vulnerability in Windows Admin Center that could allow an attacker with low-level access to seize control of an entire managed network. The flaw, tracked as...

SE Security Desk·6d ago
Cve 2026 55006 · Exchange Server

CVE-2026-55006: Patch Now to Stop Low-Privileged Users from Hijacking Your Exchange Server

Microsoft’s July 2026 Patch Tuesday release fixes a high-severity vulnerability in Exchange Server that allows an authenticated low-privileged user to escalate to full administrative control. The...

SE Security Desk·6d ago
Active Directory Federation Services · Ad Fs

Microsoft's 570-Fix Patch Tuesday: Two Zero-Days Exploited, BitLocker Bypass Disclosed

On July 14, Microsoft unloaded a record-breaking 570 security fixes across its product portfolio — the largest Patch Tuesday in the company’s history. Two of the vulnerabilities are zero-days...

SE Security Desk·6d ago
Microsoft Intune · Microsoft Security

Windows 11 July Update Lets You Pause Updates Forever—Here’s How the New Calendar Works

Windows 11 users now have a built-in, officially supported way to put off updates for months or even years. The July 2026 Patch Tuesday update replaces the old set of fixed-duration pause options...

SE Security Desk·1w ago
Asp.net Core · Cve 2026 47300

Microsoft Drops a Stealth ASP.NET Core Vulnerability with No Fix Info Yet – Here’s How to Prepare

On July 14, 2026, at 7:00 a.m. Pacific, Microsoft published a new security advisory for an elevation-of-privilege vulnerability in ASP.NET Core, tagged CVE-2026-47300. The notice arrived with a...

SE Security Desk·1w ago
Microsoft Security · Office Ole Automation

Windows Update KB5094126 Cripples Office OLE for Third-Party Software—Microsoft Pauses Rollout

Microsoft's latest June 2026 security update, KB5094126, is breaking OLE automation scenarios where third-party applications launch or control Microsoft Office. The company has placed targeted...

SE Security Desk·1w ago
Microsoft Security · Phishing-resistant Mfa

Microsoft’s Internal Security Overhaul Achieves 99.97% Phishing-Proof Logins, Sets 2029 Quantum-Safe Deadline

Microsoft has crossed a watershed moment in its own security transformation. On July 10, 2026, the company published its latest Secure Future Initiative (SFI) progress report, revealing that an...

SE Security Desk·1w ago
Deployment Rings · Microsoft Security

Microsoft Tells Admins to Speed Up Emergency Patching with Risk-Based Deployment Rings

Microsoft on May 12, 2026 issued new guidance that could slash the time it takes to deploy critical out-of-band patches from days to hours. The company is urging IT administrators to adopt risk-based...

SE Security Desk·1w ago