Microsoft Fixes Remote LSASS Vulnerability That Can Take Down Windows Domain Controllers
On July 14, 2026, Microsoft released its monthly security updates, and among the fixes is a patch for a vulnerability that should make every IT administrator sit up and take notice. CVE-2026-40378 is...
July 2026 Windows Update Closes Door on No-Authentication Network DoS in Schannel
The July 14, 2026 security updates from Microsoft patch a vulnerability in Windows Secure Channel that lets an unauthenticated attacker trigger a denial of service over a network. The flaw, tracked...
Microsoft’s July Updates Close a Backdoor in Windows Event Logs That Could Leak Your Most Sensitive Information
On July 14, 2026, Microsoft tackled a serious information-disclosure vulnerability in the Windows Event Logging Service as part of its monthly security release. The bug, tracked as CVE-2026-34348,...
Microsoft Ships Fix for PowerShell Path Traversal RCE (CVE-2026-40400) – Here’s What to Patch First
Microsoft released its July 14, 2026 security updates fixing CVE-2026-40400, a high-severity remote code execution vulnerability in Windows PowerShell that earned a CVSS 3.1 score of 8.0. The flaw...
CVE-2026-41087: File Explorer update plugs data leak—what Windows users should do
Every logged-in user on your PC could be snooping through data they shouldn’t see, thanks to a File Explorer flaw Microsoft just patched. The vulnerability, tracked as CVE-2026-41087, was disclosed...
Microsoft’s July Patch Tuesday Fixes File Explorer Flaw That Could Expose Private Data on Shared PCs
Microsoft has patched a vulnerability in Windows File Explorer that could allow someone with a local account on your PC to read private data they shouldn’t have access to. The fix arrived with the...
July 2026 Windows Updates Patch Audio Service Flaw That Leaks Event Log Memory Addresses
Microsoft’s July 14, 2026 security updates correct a vulnerability in the Windows Audio Service that exposes memory addresses belonging to the Windows Event Log service. An attacker who already has...
Microsoft Fixes Windows File Explorer Vulnerability That Leaks Data to Local Attackers—Apply July Updates Now
Microsoft’s July 14, 2026 security patch bundles a fix for CVE-2026-33842, an information‑disclosure bug in Windows File Explorer that could let an attacker who’s already logged on to your PC...
Microsoft Warns of Azure AD Infinite-Loop Flaw Triggered by Unauthenticated Attackers
Microsoft disclosed CVE-2026-50653 on July 14, 2026, an “Important” denial-of-service vulnerability in Azure Active Directory components that anyone can trigger remotely – no account, password,...
Power BI Report Server's XSS Fix Requires a Specific Build—Your Last Update May Not Be Enough
Microsoft has patched an important-rated cross-site scripting vulnerability in Power BI Report Server that could allow an authenticated attacker to inject malicious scripts into the portal. The fix...
Critical SharePoint RCE Patched a Month Ago — Is Your Server Still Exposed?
On July 14, 2026, Microsoft published details of a remote code execution vulnerability in SharePoint Server that needs no authentication, no user interaction, and can be triggered over the network....
Microsoft’s July 2026 Windows Updates Seal a Serious NTFS Security Hole—Patch Now
Microsoft’s monthly security update on July 14, 2026, delivered a fix for a heap-based buffer overflow in the NTFS file system that could allow an attacker to execute arbitrary code on your PC. The...