
[CIVN-2026-0448] Multiple vulnerabilities in Microsoft Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in Microsoft Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Systems Affected
Azure Data Manager for Energy
Azure SQL Database
Azure Data Factory
Microsoft Office Word
Microsoft Office 365
Microsoft Office LTSC
Microsoft 365 Apps
Microsoft Copilot in Azure
Azure Virtual Machines
Microsoft Partner Center
Azure ARC
Azure Logic Apps
Azure Web Apps
Microsoft Fabric
Azure Managed Instance for Apache Cassandra
Windows Remote Help
Microsoft Entra ID
Overview
Multiple vulnerabilities have been reported in Microsoft products which could allow an unauthenticated, remote attacker to elevate privileges, execute arbitrary code, disclose sensitive information, perform spoofing or cause denial of services on the affected systems.
Target Audience:
All organizations and individuals using affected Microsoft products.
Risk Assessment:
High risk of remote code execution, service disruption and sensitive information disclosure on the underlying system.
Impact Assessment:
High impact on Confidentiality, Integrity and Availability of the system.
Description
These vulnerabilities exist in the Microsoft products due to improper input validation, access control weakness or incorrect name resolution. An attacker could exploit these vulnerabilities by sending crafted inputs to the affected systems.
Successful exploitation of these vulnerabilities could allow an attacker to elevate privileges, execute arbitrary code, disclose sensitive information, perform spoofing or cause denial of services on the affected systems.
Solution
Apply appropriate updates as mentioned by the vendor:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69502
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69419
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68782
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66800
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70105
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69855
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69543
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69558
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69555
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69400
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66309
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65816
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63509
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65770
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55013
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55015
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69851
Vendor Information
Microsoft
https://www.microsoft.com/en-in
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69502
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69419
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68782
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66800
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70105
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69855
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69543
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69558
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69555
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69400
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66309
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65816
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63509
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65770
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55013
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55015
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69851
CVE Name
CVE-2026-69502
CVE-2026-69419
CVE-2026-68782
CVE-2026-66800
CVE-2026-70105
CVE-2026-69855
CVE-2026-69543
CVE-2026-69558
CVE-2026-69555
CVE-2026-69400
CVE-2026-66309
CVE-2026-65816
CVE-2026-63509
CVE-2026-65770
CVE-2026-55013
CVE-2026-55015
CVE-2026-69836
CVE-2026-69851
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqiwLwACgkQ3jCgcSdc
ys9Jkw//SgVF9HdTFlidZqiY1nRc7XO4yNEPd2v+hPH6/FhafIH2WiWtoUzAvgrM
Huac2K6Lu0ovp4SxgqvMbPcpimRwxKuVTln5ELlCLRX+yNrpvoVEQwaUUPD6Aaa3
E3stJ8czsnEVC5tso1F7Nvy8TXpgtvxZxUjpuB8UIzwt40Lx0aHwZEe+Q3Nr/H82
OwDvMi4A1xSNmnsla4EvzM41MKiSlMSYDydmaBxyIqqT6tBQHu5JB3Et49Hvbl0+
RxpNZzfcmerKMWq+1/41Fqxpu9T4kdEY02jE3Vj1+hMCl9af85YyrJx/Aqljy6Gr
DfbCn5Pdr/FSGTt8N5StV/43kkvnMjVmR142w0qSxQ90bt0v1WoCC2lFIWuCZ9FL
tTcGfCAZQMf2Feb8rR0z9a5vqw2dmJTOVIHOhHVMPXsbr3edw1rgnY0jyh62vknW
4yqmG0hSEhKzMqKBlYmmqSvzZc7kL+vazFuVSnA+0mjHr5hxdcoapxp1jxQ5SNQ+
A6ouYsbwRNmbXvEkLWzOEQwuZsvN9QdkRo9xdYPmV1hTPMeRL6JWg5kFG1aHrWWa
bmS4kmaoYDa2NYgPOGXLFpbdx8J/KV9XoidQdA7HZNRlEU7NwjjZ4blvCzVW9eTS
OeFg6vau3cjJr3o7c2+8xT9J8DSWV2PF3pVd+9g/1oFWDVwQ9fk=
=XcVu
—–END PGP SIGNATURE—–


