The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability, tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks.
The flaw affects Microsoft SQL Server and can allow...
Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users can now receive up to 100 GB of Exchange Online mailbox capacity, doubling the previous 50 GB entitlement.
The change...
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Microsoft Internet Key Exchange vulnerability, tracked as CVE-2026-33824, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks.
The flaw affects Microsoft Internet Key Exchange (IKE) Service Extensions...
CISA added a critical Microsoft SharePoint authentication flaw to its KEV catalog after CVE-2026-55040 was confirmed in active exploitation, urging organizations to secure affected on-premises environments.
CVE-2026-55040 is a weakness in Microsoft SharePoint’s authentication handling that can allow an unauthenticated...
Microsoft has issued a 60-day reminder that Windows 11 Home and Pro editions, version 24H2, will reach the end of updates on October 13, 2026.
After that date, affected devices will no longer receive Microsoft’s monthly security updates or non-security...
Public proof-of-concept exploit code is now available for CVE-2026-47301, a critical remote code execution vulnerability affecting Microsoft Configuration Manager (SCCM).
The disclosed exploit chain could allow a low-privileged domain user to gain SYSTEM-level execution on a Configuration Manager Primary Site...
Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or Configuration Manager.
The flaws could allow an attacker to execute malicious code remotely on an SCCM primary site server, potentially taking...
Microsoft is moving closer to a unified Copilot experience by merging key elements of its consumer AI assistant with the Microsoft 365 productivity environment.
The change positions Copilot as a single application for personal tasks, workplace productivity, files, collaboration, and...
Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods.
The company will also retire Microsoft-provided SMS and voice authentication for multifactor authentication, pushing organizations toward phishing-resistant...
Microsoft has released security updates for multiple Exchange Server vulnerabilities that could allow denial-of-service, privilege escalation, remote code execution, spoofing, and security feature bypass attacks.
The flaws were disclosed on August 11, 2026, as part of Microsoft’s monthly Patch Tuesday...