Articles from July 14, 2026
Browse all Windows news articles published on July 14, 2026
Microsoft Ships AD FS Fix, But Automatic Remediation Is Months Away — Here’s How to Secure Your Keys Now
Microsoft shipped a security fix on July 14, 2026, for a dangerous elevation-of-privilege flaw in Active Directory Federation Services (AD FS) that attackers are already exploiting. But any...
High-Severity CVE-2026-55948: Excel Workbook Flaw Demands Quick Patch
Microsoft on July 14, 2026 detailed CVE-2026-55948, a use-after-free vulnerability in Microsoft Office Excel that carries a CVSS 3.1 score of 7.8. An attacker who crafts a malicious workbook can...
Excel Patch for July 2026 Closes Remote Code Execution Hole Exploited via Malicious Files
On July 14, 2026, Microsoft released a security update for Microsoft Excel that fixes a vulnerability allowing attackers to run arbitrary code on a victim’s machine simply by having them open a...
CVE-2026-54988: Microsoft's Excel Update Fixes Data Leak and Crash Flaw
On July 14, Microsoft released a security update for Microsoft Office Excel that patches a memory-read vulnerability rated Medium severity. Despite the modest score, the flaw can crash Excel or cause...
Microsoft Deploys Fix for Excel Heap Overflow That Can Crash Apps and Expose Data
Microsoft shipped a security update on July 14, 2026, that plugs a heap-based buffer overflow in Excel capable of leaking information and abruptly terminating the application when a user opens a...
Microsoft Patches Excel Flaw That Turns a Simple Spreadsheet into a Backdoor
Microsoft issued a security fix on July 14, 2026, for a flaw in Excel that can give attackers full control of a PC when a victim opens a poisoned spreadsheet. The vulnerability, tracked as...
Microsoft Patches SharePoint Spoofing Flaw That Can Leak Data Without a Click
Microsoft’s July 14, 2026 security update fixes a vulnerability in on-premises SharePoint Server that lets already-authenticated attackers spoof content and siphon sensitive documents — no...
Visual Studio Code 1.128.1 Fixes Command Injection Flaw; Update Now to Block Code Execution Attacks
Microsoft released Visual Studio Code version 1.128.1 on July 14, 2026, patching a high-severity command-injection vulnerability tracked as CVE-2026-50520. The flaw allows an attacker to execute...
CVE-2026-55144: Windows Crypto Bug Exposes Confidential Data to Local Attackers – July 2026 Fix Urged
Microsoft’s July 14, 2026 security update seals a dangerous hole in Windows’ core cryptographic engine that could let intruders with minimal access pry open protected data. CVE-2026-55144, rated...
Microsoft Fixes SQL Server Privilege Escalation Bug on 2016's End-of-Support Date
Microsoft's July 14, 2026 Patch Tuesday brought a fix for CVE-2026-55002, an elevation-of-privilege vulnerability in SQL Server that could allow an authenticated local attacker to take full control...
Your SQL Servers Are Vulnerable: Apply Microsoft’s July 2026 Fix for CVE-2026-54118 Now
On July 14, 2026, Microsoft published a security update that patches a critical remote code execution (RCE) hole in Microsoft SQL Server. Tracked as CVE-2026-54118, the vulnerability scored 8.8 on...
SQL Server 2025 RCE Vulnerability Demands Urgent Patching—Here’s How to Protect Your Data
Microsoft has disclosed a serious security flaw in SQL Server 2025 that could allow an attacker with even low-level database access to completely take over the underlying server. The vulnerability,...