started · updated
Microsoft releases security updates for 398 vulnerabilities
Microsoft has released a major security update addressing 398 vulnerabilities across its Windows operating systems and software infrastructure. The update includes fixes for Windows 10 and Windows 11, with 42 of the vulnerabilities classified as critical.
Of particular concern are three zero-day vulnerabilities that have already been identified as being actively exploited by attackers. These flaws affect components such as the Windows User Profile Service, a network driver (afd.sys), and a driver for Windows container isolation, potentially allowing attackers to gain elevated system privileges.
Additionally, Microsoft issued a specific hotfix (KB38232642) for Microsoft Configuration Manager (formerly SCCM) to address CVE-2026-47301. This vulnerability, which carries a CVSS score of 8.8, was identified by security researcher Omri Baso. While the hotfix addresses part of the issue, it is part of a larger chain of four vulnerabilities that could enable remote code execution (RCE).