Security 10973 Published by Philipp Esselbach 0

Microsoft has released its July 2026 security updates, addressing 622 Microsoft-assigned CVEs and 428 Chromium vulnerabilities across Windows, Office, and Azure. Organizations should prioritize immediate patching for critical flaws under active exploitation, including the BitLocker security bypass and Active Directory Federation Services privilege escalation. This release also brings generally available hotpatching for Windows Server on Azure, TDI transport hardening, and a bundled curl upgrade to version 8.21.0. Administrators can deploy the fixes via Windows Update or the Microsoft Update Catalog, though Office 2016 users must manage 18 individual patches rather than a single cumulative update.

Security 10973 Published by Philipp Esselbach 0

Microsoft just released the June 2026 security update, and the patch count alone will make most IT admins sweat. The release tackles critical remote code execution flaws in HTTP.sys, patches firmware checks in Secure Boot and BitLocker, and closes dozens of Office and Exchange vulnerabilities that have been sitting in the wild. Administrators should always apply the latest servicing stack update first, because an outdated stack will silently skip newer security packages and leave systems exposed. Once the main patch installs and the system reboots, networks and workstations will stay out of the crosshairs until the next rollout.

Security 10973 Published by Philipp Esselbach 0

The May 2026 Security Update delivers 265 patches, with the bulk of the work focusing on Chromium browser hardening and critical Windows kernel fixes. High severity flaws in the TCP/IP stack and Win32k graphics subsystem are addressed to block privilege escalation and remote code execution attempts. Office components and Azure cloud services also receive important remote code execution patches that require a current servicing stack for smooth deployment. Users should install the update immediately, verify the new build number after reboot, and check Microsoft's known issues list to avoid unexpected deployment delays.

Security 10973 Published by Philipp Esselbach 0

Microsoft's April 2026 Security Updates cover a massive list of vulnerabilities, yet the real priority involves fixing Remote Desktop and BitLocker flaws that could allow attackers to take control or bypass encryption. Several critical issues marked as exploitation more likely include holes in the Windows Boot Loader and kernel components that require immediate attention from anyone running sensitive workloads. History shows these kernel patches sometimes trigger glitches with Windows Hello or Explorer, making a system restore point essential before installation. Run the update manually through Settings and reboot immediately to ensure all security fixes load correctly without leaving the system vulnerable overnight.

Security 10973 Published by Philipp Esselbach 0

Microsoft's March 2026 security updates include 83 new CVE fixes affecting various products, including Windows Server core services and Azure IoT Explorer. The most critical patch is a CVE-rated 9.8 in the Microsoft Devices Pricing Program, which could allow an attacker to read sensitive telemetry if they send a malformed request. Hotpatching is now available for Azure VM images, allowing users to apply patches without restarting their virtual machines. Users should prioritize applying patches with CVSS scores above 8 and consider their exposure to vulnerabilities when deciding which patches to install first.

Security 10973 Published by Philipp Esselbach 0

Microsoft has released the February 2026 updates with 59 security updates to patch various vulnerabilities, including a high-severity Notepad app flaw and an Azure SDK vulnerability with a base score of 9.8. The updates also address lower-score bugs that can cause crashes or data loss on mobile devices.

Security 10973 Published by Philipp Esselbach 0

Notepad++ users who ran older versions or had auto-updates turned on may have been affected by a state-sponsored hacking incident in June-December 2025, which compromised the updater by redirecting requests to malicious mirrors serving unsigned installers. To identify if your installation was hit, look for unusual update dialog pop-ups with mismatched version numbers and larger installer sizes than usual. Immediate actions include downloading Notepad++ 8.9.1 from the official site, verifying its signature using the Digital Signatures tab, disabling auto-updates, and running the installer as Administrator to enforce TLS certificate validation. Additionally, if you're using a shared hosting environment, change your FTP/SFTP, SSH, and MySQL passwords immediately due to potential credential theft during the hack.

Security 10973 Published by Philipp Esselbach 0

Microsoft has released its January 2026 security updates, addressing a total of 112 separate vulnerabilities across various parts of the Windows operating system and server software. The updates aim to resolve these issues in relevant components, including critical vulnerabilities in the Windows Server Update Service component with a CVSS score of 8.1.

Security 10973 Published by Philipp Esselbach 0

Microsoft has released its December security updates, covering 57 vulnerabilities across various components such as PowerShell, Projected File System, and Storage VSP Driver. The update also addresses moderate-severity issues in Edge on iOS devices and non-Microsoft vulnerabilities in Chromium-based web browsers like Edge. In addition to the security fixes, Microsoft has provided detailed information online about new features, including enhanced safety measures and improved transparency through machine-readable VEX files. The updates also include hotpatching for virtual machines running Windows Server Azure Edition, with Microsoft recommending Extended Security Updates (ESU) for older systems without ESU enabled.

Security 10973 Published by Philipp Esselbach 0

Microsoft has released its November 2025 security patches, addressing a total of 63 Common Vulnerabilities and Exposures (CVEs) across various areas of the Windows environment. The updates include fixes for Nuance PowerScribe software, Configuration Manager, Microsoft Office Excel, SQL Server, Azure Monitor Agent, Windows Smart Card components, DirectX, and several other applications and services. Many of these vulnerabilities have high base scores on the CVSS scale but are considered difficult to exploit due to specific requirements or conditions needed to trigger them. The patches aim to address multiple issues within Microsoft Office Excel alone, including a few with the highest score so far in this update cycle.

Security 10973 Published by Philipp Esselbach 0

The October 2025 security update includes 175 Microsoft CVEs, including the agere Windows Modem Driver, Microsoft PowerShell, Windows Failover Cluster, Azure Connected Machine Agent, Microsoft Brokering File System, Virtual Secure Mode, Microsoft Graphics Component, Windows Kernel, Windows Device Association Broker service, Windows Digital Media, Windows Hello, Windows Digital Media, Microsoft Exchange Server, Visual Studio,.NET,.NET Framework, Visual Studio, Azure Monitor, Windows Storage Management Provider, Windows BitLocker, Windows PrintWorkflowUserSvc, and Windows BitLocker. 

Security 10973 Published by Philipp Esselbach 0

Microsoft has released a set of critical security updates addressing 86 Microsoft CVEs and 5 non-Microsoft CVEs, including fixes for various products such as SQL Server, Azure Windows Virtual Machine Agent, and Windows Routing and Remote Access Service (RRAS). The update also includes defense-in-depth updates to improve security-related features. 

Security 10973 Published by Philipp Esselbach 0

Microsoft has released the August 2025 security update, which fixes 111 Microsoft CVEs related to various products like Windows Hyper-V, Azure Virtual Machines, Microsoft Office SharePoint, Microsoft Edge for Android, Microsoft Graphics Component, Microsoft Dynamics 365 (on-premises), Windows Routing and Remote Access Service (RRAS), Windows NTFS, Remote Access Point-to-Point Protocol (PPP) EAP-TLS, Windows Win32K - GRFX, Windows Distributed Transaction Coordinator, and Windows Cloud Files Mini Filter Driver.

The update addresses vulnerabilities in the following components: Remote Desktop Server, Windows DirectX, Windows Installer, Graphics Kernel, Windows Message Queuing, Windows Media, Windows PrintWorkflow UserSvc, Windows NT OS Kernel, Windows Kernel, Windows Streaming WOW Thunk Service Driver, Desktop Windows Manager, Windows Local Security Authority Subsystem Service (LSASS), Windows Remote Desktop Services, Windows Push Notifications, SQL Server, Microsoft Dynamics 365 (on-premises), and Azure File Sync. 

Security 10973 Published by Philipp Esselbach 0

Microsoft has released the July 2025 security update release, which includes 130 Microsoft CVEs, including Service Fabric, Windows Kernel, Remote Desktop Client, Windows Visual Basic Scripting, Microsoft Intune, Virtual Hard Disk (VHDX), Microsoft Input Method Editor (IME), Windows Storage VSP Driver, Windows GDI, Windows Event Tracing, Universal Print Management Service, Windows Cred SSProvider Protocol, Azure Monitor Agent, Microsoft Input Method Editor (IME), Microsoft PC Manager, Microsoft Office, Windows MBT Transport driver, Windows Routing and Remote Access Service (RRAS), Windows Hyper-V, Windows Connected Devices Platform Service, Windows BitLocker, Windows Update Service, Windows SMB, Windows Virtualization-Based Security (VBS) Enclave, Microsoft MPEG-2 Video Extension, Windows Kernel, Windows Secure Kernel Mode, Windows Office Excel, Windows Remote Desktop Licensing Service, Windows SSDP Service, HID class driver, Remote Desktop Client, Windows Universal Plug and Play (UPnP) Device Host, Windows AppX Deployment Service, Windows Cryptographic Services, Windows Routing and Remote Access Service (RRAS), Windows TDX.sys, Windows Event Tracing, Windows Ancillary Function Driver for WinSock, Windows Routing and Remote Access Service (RRAS), Windows User-Mode Driver Framework Host, Workspace Broker, Windows Kernel, Windows Win32K - ICOMP, and Windows Routing and Remote Access Service (RRAS).

Security 10973 Published by Philipp Esselbach 0

Microsoft has released the June 2025 security updates, including 66 CVEs for Windows Storage Management Provider, Windows Cryptographic Services,.NET and Visual Studio, Windows Remote Desktop Services, Windows Win32K - GRFX, Windows Common Log File System Driver, Windows Installer, Remote Desktop Client, Windows Media, Windows SMB, Windows Recovery Driver, Windows Storage Port Driver, Windows Local Security Authority Subsystem Service (LSASS), Windows DHCP Server, Windows DWM Core Library, WebDAV, Windows DWM Core Library, Windows Kernel, Windows Standards-Based Storage Management Service, App Control for Business (WDAC), Windows Netlogon, Windows KDC Proxy Service (KPSSVC), Windows SMB, Windows Installer, Windows Shell, Microsoft Office, SharePoint, Microsoft Office Excel, Microsoft Office Word, Microsoft Office Outlook, Microsoft Office SharePoint, Microsoft Office Excel, Microsoft Office PowerPoint, Microsoft Office Outlook, Microsoft Office, Microsoft Office SDK, Power Automate, Microsoft AutoUpdate (MAU), Windows Hello, and Nuance Digital Engagement Platform.

Security 10973 Published by Philipp Esselbach 0

Microsoft has published the security updates for May 2025, which encompass Azure DevOps, Microsoft Edge (Chromium-based), Azure Automation, Azure Storage Resource Provider, Microsoft Dataverse, and Microsoft Power Apps. Microsoft has republished five non-Microsoft CVEs. The blog posts on the Security Update Guide have been revised to enhance transparency and support regarding CVEs assigned by industry partners. Updates for Windows 10 and Windows 11 are cumulative, incorporating all security fixes and non-security updates accessible through the Microsoft Update Catalog. The Windows Lifecycle Facts Sheet offers detailed information regarding the lifecycle and support dates for these operating systems. Organizations utilizing Windows Server 2008 R2 or 2008 are required to acquire the Extended Security Update to maintain access to security updates.

Security 10973 Published by Philipp Esselbach 0

Microsoft has announced the release of 126 security updates for April 2025, addressing a total of 126 CVEs. The recent updates cover a range of services and applications, including Visual Studio Code, Windows Standards-Based Storage Management Service, Windows Local Security Authority (LSA), Windows NTFS, Windows Routing and Remote Access Service (RRAS), Windows Update Stack, Windows Telephony Service, Windows DWM Core Library, Microsoft Edge (Chromium-based), Azure Local Cluster, Windows Hello, Windows BitLocker, Windows USB Print Driver, Windows Digital Media, Windows Cryptographic Services, Microsoft Office, Windows Kerberos, Windows Kernel, Windows Secure Channel, Windows Local Session Manager (LSM), Windows LDAP, Windows upnphost.dll, Windows Media, Windows Subsystem for Linux, Windows Remote Desktop Services, Windows Defender Application Control, and RPC Endpoint Mapper Service.

Security 10973 Published by Philipp Esselbach 0

Fort Firewall 3.16.6 has been released and introduces a "Connections" button, a "Auto-Learn Off" flag for programs, a "Trace Driver Events" flag for logs, and a "Driver" flag to address the default action on the Global Rule.

Security 10973 Published by Philipp Esselbach 0

Microsoft has published the March 2025 security update release covering 57 Microsoft CVEs, which include the Windows exFAT File System, Azure Agent Installer, Windows MapUrlToZone, Windows Remote Desktop Services, .NET, Windows Win32 Kernel Subsystem, Microsoft Streaming Service, Windows Hyper-V, Azure CLI, Windows Routing and Remote Access Service (RRAS), Windows NTLM, Windows USB Video Driver, Windows Telephony Server, Microsoft Office, Windows Common Log File System Driver, Windows Mark of the Web (MOTW), Windows Kernel-Mode Drivers, ASP.NET Core & Visual Studio, Windows File Explorer, Microsoft Local Security Authority Server (lsasrv), Microsoft Office Excel, Windows Cross Device Service, Microsoft Office Word, Microsoft Office Access, Visual Studio Code, Microsoft Management Console, Microsoft Edge (Chromium-based), and Remote Desktop Client. Furthermore, 10 non-Microsoft CVEs have been republished.

Security 10973 Published by Philipp Esselbach 0

Microsoft has announced the release of 63 security updates, addressing a range of vulnerabilities across various platforms including Windows 10, Windows DHCP Client, Windows Message Queuing, Windows Resilient File System (ReFS) Deduplication Service, Windows CoreMessaging, Azure Network Watcher, Windows Telephony Service, Microsoft Surface, Microsoft High Performance Compute Pack (HPC) Linux Node Agent, Windows Telephony Service, Windows Telephony Server, Visual Studio, Windows Routing and Remote Access Service (RRAS), Windows Internet Connection Sharing (ICS), Windows CoreMessaging, Windows Kernel, Windows Win32 Kernel Subsystem, Windows LDAP, Windows NTLM, Windows DHCP Server, Microsoft Office Excel, Windows Storage, Microsoft Office SharePoint, Windows DWM Core Library, Windows Ancillary Function Driver for WinSock, Windows Setup Files Cleanup, Windows Disk Cleanup Tool, Microsoft AutoUpdate (MAU), and Visual Studio Code.