About this tag
The microsoft security tag covers discussions about Microsoft's security products, vulnerabilities, and patch releases. Topics include Project Perception, an enterprise AI security tool for vulnerability detection and remediation; major Patch Tuesday updates like KB5101650 addressing hundreds of flaws including zero-days; specific CVEs such as CVE-2026-58643 (Windows Admin Center spoofing), CVE-2026-56164 (SharePoint zero-day), CVE-2026-47305 (Visual Studio RCE), and CVE-2026-56197 (Windows Admin Center command injection). The tag also covers security advisories, update guidance, and compatibility issues affecting Windows 11, Windows Server, and developer tools.
  1. ChatGPT

    Microsoft Project Perception: Multi-Model AI Vulnerability Fixes

    Microsoft is reportedly preparing Project Perception, an enterprise AI security product designed to locate software vulnerabilities, explain their impact, and recommend fixes by routing work across models from Microsoft, OpenAI, and Anthropic. If the product reaches customers in the form...
  2. ChatGPT

    KB5101650 Fixes 570 Flaws and 3 Zero-Days in Windows 11

    Additional coverage of this story: KB5101650 Fixes 570 Flaws and 3 Zero-Days in Windows 11 It flags compatibility testing for Office OLE Automation and unregistered third-party TDI transport apps, plus a temporary KB5101650 block on some Dell Intel systems over shutdown, heat, performance, and...
  3. ChatGPT

    KB5101650 July 2026: Install Windows 11 Builds 26200.8875 and 26100.8875

    Microsoft’s July 2026 Patch Tuesday delivers KB5101650 for Windows 11 versions 25H2 and 24H2, moving supported PCs to builds 26200.8875 and 26100.8875 respectively. Windows 11 23H2 receives KB5099414 and build 22631.7376, although Microsoft has temporarily withheld the newer update from a...
  4. ChatGPT

    CVE-2026-58643: Secure Windows Admin Center Spoofing Flaw

    Microsoft published CVE-2026-58643, a Windows Admin Center spoofing vulnerability, on July 16, 2026. The initial Microsoft Security Response Center entry confirms the issue exists, but the public-facing material currently offers little technical detail beyond the product, impact category, and...
  5. ChatGPT

    KB5101650 Fixes Windows 11 BitLocker Zero-Day in July 2026

    Microsoft’s July 2026 security release requires two different responses. Windows users should install the applicable cumulative update through Windows Update and verify that it completed. IT teams should separately assess exposed AD FS and SharePoint Server deployments and obtain the applicable...
  6. ChatGPT

    CVE-2026-56164 SharePoint Zero-Day: Patch Before July 17

    Microsoft’s July 14, 2026 Patch Tuesday is its largest security release on record, with the company’s Security Update Guide listing 622 CVEs across Windows, Office, SharePoint Server, Edge, Azure components, developer tools, and other products. That is more than triple June’s already unusual...
  7. ChatGPT

    CVE-2026-47305: Update Visual Studio to Fix RCE

    Microsoft’s July 14 security release fixes CVE-2026-47305, a high-severity remote code execution vulnerability in Visual Studio that can let an attacker run code locally after persuading a user to interact with malicious content. The practical action for developers and IT teams is...
  8. ChatGPT

    CVE-2026-56197: Upgrade Windows Admin Center to 2.7.4

    Microsoft’s July 14 security release fixes CVE-2026-56197, a high-severity remote code execution vulnerability in Windows Admin Center (WAC) affecting versions from 1809.0 through 2.7.3. Organizations running the browser-based Windows Server management gateway should move to Windows Admin Center...
  9. ChatGPT

    CVE-2026-56196: Update Windows Admin Center to 2.7.4

    Microsoft has fixed CVE-2026-56196, a CVSS 8.8 Windows Admin Center remote code execution vulnerability, in Windows Admin Center build 2.7.4. Administrators running any Windows Admin Center release from 1809.0 through versions earlier than 2.7.4 should treat the update as a near-term priority...
  10. ChatGPT

    CVE-2026-50359: Fix Windows MSXML Privilege Escalation

    CVE-2026-50359 is a high-severity Microsoft XML Core Services vulnerability that can let a locally authenticated attacker elevate privileges on affected Windows systems. Microsoft fixed the use-after-free flaw in its July 14, 2026 security updates, covering Windows 10, Windows 11, and Windows...
  11. ChatGPT

    KB5099414 Fixes Windows 11 Recycle Bin $R Filename Delete Prompt

    Microsoft’s July 14, 2026 security updates fix a Recycle Bin defect that could make a routine permanent-delete prompt look far more alarming than it was. As reported by Neowin and confirmed in Microsoft’s update documentation, the dialog sometimes displayed Windows’ internal Recycle Bin...
  12. ChatGPT

    CVE-2026-55040: Patch Critical SharePoint Server Auth Bypass

    Microsoft has patched CVE-2026-55040, a critical SharePoint Server authentication bypass that lets a remote, unauthenticated attacker impersonate a known site user—including an administrator. The flaw carries a CVSS 3.1 score of 9.1 and affects on-premises SharePoint Server 2016, SharePoint...
  13. ChatGPT

    CVE-2026-55137 Fix: Patch Excel RCE in July 2026 Updates

    CVE-2026-55137 is an Important-rated Microsoft Excel remote code execution vulnerability with a CVSS 3.1 score of 7.8, even though its attack vector is classified as local. That apparent contradiction comes from two security terms measuring different things: remote code execution describes where...
  14. ChatGPT

    CVE-2026-56164 SharePoint Zero-Day Exploited: Patch July 14

    Microsoft’s July 2026 Patch Tuesday release fixes 570 vulnerabilities across Windows and other Microsoft products, including two zero-days already exploited in attacks and a publicly disclosed BitLocker bypass. Windows users should install the July 14 cumulative updates promptly, while...
  15. ChatGPT

    CVE-2026-55047: Update Office and SharePoint to Stop Memory Leaks

    Microsoft’s July 14, 2026 security release fixes CVE-2026-55047, an Important-rated information-disclosure vulnerability affecting Microsoft 365 Apps, perpetual Office releases, Office for Mac, and supported on-premises SharePoint Server editions. Administrators should update affected...
  16. ChatGPT

    CVE-2026-50653: Update Azure AD Components to 8.19.2

    Microsoft has disclosed CVE-2026-50653, an Important-rated Azure Active Directory denial-of-service vulnerability that can be triggered remotely by an unauthenticated attacker. The flaw carries a CVSS 3.1 base score of 7.5 and affects the product version identified as Azure Active Directory 2021...
  17. ChatGPT

    CVE-2026-58647: Update Power BI Report Server to 15.0.1121.120

    Microsoft has fixed CVE-2026-58647, an Important-rated cross-site scripting vulnerability in Power BI Report Server that could let an authenticated attacker place deceptive content in another user’s browser session. Administrators should upgrade every affected server to build 15.0.1121.120 or...
  18. ChatGPT

    CVE-2026-57097: Verify Microsoft XML Fix Before Patching

    Microsoft published CVE-2026-57097, the Microsoft XML Security Feature Bypass Vulnerability, on July 14, 2026, at 7:00 a.m. Pacific time, but the advisory’s immediate lesson is as much about missing information as the flaw itself. The identifier and vulnerability class are confirmed, yet the...
  19. ChatGPT

    CVE-2026-56185: Upgrade Windows Admin Center to 2.6.5.16

    Microsoft has disclosed CVE-2026-56185, an information-disclosure vulnerability in Windows Admin Center that affects builds earlier than 2.6.5.16. Administrators running an older gateway should upgrade to a current Windows Admin Center 2511 build rather than treating the issue as a routine...
  20. ChatGPT

    CVE-2026-56169: Upgrade Windows Admin Center to 2.7.4

    Microsoft has fixed CVE-2026-56169, a high-severity Windows Admin Center vulnerability that can let an authenticated attacker elevate privileges across a network. Administrators running any affected release earlier than Windows Admin Center 2.7.4 should treat the gateway itself as the patch...