Multiple vulnerabilities in Microsoft products (August 17, 2026)
Multiple vulnerabilities have been discovered in Microsoft products. They allow an attacker to cause remote arbitrary code execution and privilege escalation.
CSIRTS triage
- What
- Multiple Microsoft products contain vulnerabilities allowing remote code execution and privilege escalation.
- Who is affected
- Organizations using affected Microsoft products are at risk.
- Urgency
- High priority; multiple Microsoft products with RCE and privilege escalation capabilities warrant rapid patching.
- Action
- Identify affected Microsoft products from the CVE advisory and apply corresponding security updates.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1035/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-694140.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-505230.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69414 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50523 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Microsoft PowerShell: Vulnerability enables code executioncert-bund
- high[NEW] [UNPATCHED] [high] Microsoft Malware Protection Engine and Defender: Vulnerability enables gaining admin…cert-bund
- highCVE-2026-69414: Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in …nvd
- highCVE-2026-50523: Improper neutralization of special elements used in a command ('command injection') in Microso…nvd
- highCVE-2026-69414: Microsoft Defender Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-50523: Microsoft PowerShell Remote Code Execution Vulnerabilitymsrc
Recent advisories for Microsoft products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-60998: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (co…nvd · 2026-08-18
- critical[NEW] [critical] Microsoft Windows products: Multiple vulnerabilitiescert-bund · 2026-08-18
- critical[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilitiescert-bund · 2026-08-14
- high[NEW] [high] Microsoft Office Products: Multiple Vulnerabilitiescert-bund · 2026-08-13
- critical[NEW] [critical] Microsoft Office products: Multiple vulnerabilitiescert-bund · 2026-08-13
- unknownMultiple vulnerabilities in Microsoft products (August 12, 2026)cert-fr-avis · 2026-08-12
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Oracle Virtualization (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle Weblogic (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Axis products (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Google Chrome (August 19, 2026)2026-08-19
- unknownMultiple vulnerabilities in Oracle MySQL (August 19, 2026)2026-08-19