Microsoft threat watch

Security Update Guide, advisories, and patch watch.

Vendor watch hub

What this page covers

The Microsoftwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Microsoft activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

1477

Active

1071

Featured

1107

Unique CVEs

20

Most recent entry

May 7, 2026, 5:16 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·Microsoft Security Update Guide (MSRC), CISA KEV, and NVD

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Watch items

Recent Microsoft watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

azure ai foundry vulnerability (CVE-2026-35435)

CRITICAL
watchNVDCVE-2026-35435

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

May 7, 2026, 5:16 PMOfficial source

Chromium: CVE-2026-7896 Integer overflow in Blink (CVE-2026-7896)

activeVendor advisoryCVE-2026-7896

Information published.

May 7, 2026, 9:00 AMOfficial source

Microsoft Team Events Portal Information Disclosure Vulnerability (CVE-2026-33823)

critical
watchVendor advisoryCVE-2026-33823

Information published.

May 7, 2026, 9:00 AMOfficial source

Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability (CVE-2026-33844)

critical
watchVendor advisoryCVE-2026-33844

Information published.

May 7, 2026, 9:00 AMOfficial source

Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability (CVE-2026-40379)

critical
watchVendor advisoryCVE-2026-40379

Information published.

May 7, 2026, 9:00 AMOfficial source

Azure DevOps Information Disclosure Vulnerability (CVE-2026-42826)

critical
watchVendor advisoryCVE-2026-42826

Information published.

May 7, 2026, 9:00 AMOfficial source

Azure Cloud Shell Spoofing Vulnerability (CVE-2026-35428)

critical
watchVendor advisoryCVE-2026-35428

Information published.

May 7, 2026, 9:00 AMOfficial source

Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability (CVE-2026-33109)

critical
watchVendor advisoryCVE-2026-33109

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7900 Heap buffer overflow in ANGLE (CVE-2026-7900)

activeVendor advisoryCVE-2026-7900

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7898 Use after free in Chromoting (CVE-2026-7898)

activeVendor advisoryCVE-2026-7898

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7909 Inappropriate implementation in ServiceWorker (CVE-2026-7909)

activeVendor advisoryCVE-2026-7909

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7906 Use after free in SVG (CVE-2026-7906)

activeVendor advisoryCVE-2026-7906

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7904 Out of bounds read in Fonts (CVE-2026-7904)

activeVendor advisoryCVE-2026-7904

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7899 Out of bounds read and write in V8 (CVE-2026-7899)

activeVendor advisoryCVE-2026-7899

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7907 Use after free in DOM (CVE-2026-7907)

activeVendor advisoryCVE-2026-7907

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7902 Out of bounds memory access in V8 (CVE-2026-7902)

activeVendor advisoryCVE-2026-7902

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7901 Use after free in ANGLE (CVE-2026-7901)

activeVendor advisoryCVE-2026-7901

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7903 Integer overflow in ANGLE (CVE-2026-7903)

activeVendor advisoryCVE-2026-7903

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7908 Use after free in Fullscreen (CVE-2026-7908)

activeVendor advisoryCVE-2026-7908

Information published.

May 7, 2026, 9:00 AMOfficial source

Chromium: CVE-2026-7910 Use after free in Views (CVE-2026-7910)

activeVendor advisoryCVE-2026-7910

Information published.

May 7, 2026, 9:00 AMOfficial source

Related vendors

Other productivity vendors in the radar

Vendor watch FAQ

Common questions

What is the Microsoft threat watch page?

It is the Microsoft-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Microsoft watch page?

Use it to confirm whether current Microsoft issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Microsoft security issues?

Yes. ITECS can help map Microsoft advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.