Microsoft Security
The latest Microsoft Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Warns of Azure AD Infinite-Loop Flaw Triggered by Unauthenticated Attackers
Microsoft disclosed CVE-2026-50653 on July 14, 2026, an “Important” denial-of-service vulnerability in Azure Active Directory components that anyone can trigger remotely – no account, password,...
Power BI Report Server's XSS Fix Requires a Specific Build—Your Last Update May Not Be Enough
Microsoft has patched an important-rated cross-site scripting vulnerability in Power BI Report Server that could allow an authenticated attacker to inject malicious scripts into the portal. The fix...
CVE-2026-57097: Microsoft Confirms XML Security Bypass, but Details Are Scarce
Microsoft has published a new security advisory for a vulnerability identified as CVE-2026-57097, a security feature bypass in Microsoft XML, but the notice leaves critical questions unanswered....
CVE-2026-56185: Your Windows Admin Center Is Likely Vulnerable — Here’s the Fix That Windows Update Misses
On July 14, 2026, Microsoft published a security advisory for an information-disclosure vulnerability in Windows Admin Center — but the fix had already been available for more than three months....
Microsoft Fixes Network-Elevation Flaw in Windows Admin Center – Patch Now
Microsoft has patched a high-severity vulnerability in Windows Admin Center that could allow an attacker with low-level access to seize control of an entire managed network. The flaw, tracked as...
CVE-2026-55006: Patch Now to Stop Low-Privileged Users from Hijacking Your Exchange Server
Microsoft’s July 2026 Patch Tuesday release fixes a high-severity vulnerability in Exchange Server that allows an authenticated low-privileged user to escalate to full administrative control. The...
Microsoft's 570-Fix Patch Tuesday: Two Zero-Days Exploited, BitLocker Bypass Disclosed
On July 14, Microsoft unloaded a record-breaking 570 security fixes across its product portfolio — the largest Patch Tuesday in the company’s history. Two of the vulnerabilities are zero-days...
Windows 11 July Update Lets You Pause Updates Forever—Here’s How the New Calendar Works
Windows 11 users now have a built-in, officially supported way to put off updates for months or even years. The July 2026 Patch Tuesday update replaces the old set of fixed-duration pause options...
Microsoft Drops a Stealth ASP.NET Core Vulnerability with No Fix Info Yet – Here’s How to Prepare
On July 14, 2026, at 7:00 a.m. Pacific, Microsoft published a new security advisory for an elevation-of-privilege vulnerability in ASP.NET Core, tagged CVE-2026-47300. The notice arrived with a...
Windows Update KB5094126 Cripples Office OLE for Third-Party Software—Microsoft Pauses Rollout
Microsoft's latest June 2026 security update, KB5094126, is breaking OLE automation scenarios where third-party applications launch or control Microsoft Office. The company has placed targeted...
Microsoft’s Internal Security Overhaul Achieves 99.97% Phishing-Proof Logins, Sets 2029 Quantum-Safe Deadline
Microsoft has crossed a watershed moment in its own security transformation. On July 10, 2026, the company published its latest Secure Future Initiative (SFI) progress report, revealing that an...
Microsoft Tells Admins to Speed Up Emergency Patching with Risk-Based Deployment Rings
Microsoft on May 12, 2026 issued new guidance that could slash the time it takes to deploy critical out-of-band patches from days to hours. The company is urging IT administrators to adopt risk-based...