Understanding the 2026 Microsoft Vulnerability Landscape: Insights & Expert Panel Discussion
with Morey Haber, Chief Security Advisor; James Maude, Field Chief Technology Officer
Understanding the 2026 Microsoft Vulnerability Landscape: Insights & Expert Panel Discussion
Get Instant Access to this Content
Learn more about how to secure your business from threats in places you didn't even know existed.
About the session
Link copied
Now in its 13th year, the Microsoft Vulnerabilities Report from BeyondTrust has become a trusted resource for cybersecurity professionals seeking to better understand the shifting risk landscape within Microsoft’s ecosystem. Based on a comprehensive analysis of Microsoft vulnerability disclosures from the past year, the 2026 edition reveals a critical inflection point: while total vulnerabilities have slightly declined, critical vulnerabilities have surged, and identity-driven attack paths continue to dominate.
In this session, BeyondTrust experts Morey Haber, James Maude, and Christopher Hills examined how AI is reshaping vulnerability discovery and exploitation, and why Elevation of Privilege vulnerabilities remain the most consequential risk.
More importantly, they’ll explore what this means for defenders, and how organizations can shift to a privilege-centric, identity-first approach to reduce real-world attack paths.
Whatyou'll learn in this session:
Key vulnerability trends across Microsoft products, including 5-year patterns and standout CVEs
Why “Elevation of Privilege” and other identity-based risks remain top attack vectors
How enforcing least privilege, zero trust, and other core security principles can dramatically reduce risk
Meet the Speaker
Link copied
Morey Haber
Chief Security Advisor
Morey J. Haber is the Chief Security Advisor at BeyondTrust. As the Chief Security Advisor, Morey is the lead identity and technical evangelist at BeyondTrust. He has more than 25 years of IT industry experience and has authored four books: Privilege
... read more
Morey J. Haber is the Chief Security Advisor at BeyondTrust. As the Chief Security Advisor, Morey is the lead identity and technical evangelist at BeyondTrust. He has more than 25 years of IT industry experience and has authored four books: Privileged Attack Vectors, Asset Attack Vectors, Identity Attack Vectors, and Cloud Attack Vectors. Morey has previously served as BeyondTrust’s Chief Security Officer, Chief Technology, and Vice President of Product Management during his nearly 12-year tenure. In 2020, Morey was elected to the Identity Defined Security Alliance (IDSA) Executive Advisory Board, assisting the corporate community with identity security best practices. He originally joined BeyondTrust in 2012 as a part of the acquisition of eEye Digital Security, where he served as a Product Owner and Solutions Engineer, since 2004. Prior to eEye, he was Beta Development Manager for Computer Associates, Inc. He began his career as Reliability and Maintainability Engineer for a government contractor building flight and training simulators. Morey earned a Bachelor of Science degree in Electrical Engineering from the State University of New York at Stony Brook.
Morey J. Haber is the Chief Security Advisor at BeyondTrust. As the Chief Security Advisor, Morey is the lead identity and technical evangelist at BeyondTrust. He has more than 25 years of IT industry experience and has authored four books: Privilege
...
read more
Morey Haber
Chief Security Advisor
Morey J. Haber is the Chief Security Advisor at BeyondTrust. As the Chief Security Advisor, Morey is the lead identity and technical evangelist at BeyondTrust. He has more than 25 years of IT industry experience and has authored four books: Privileged Attack Vectors, Asset Attack Vectors, Identity Attack Vectors, and Cloud Attack Vectors. Morey has previously served as BeyondTrust’s Chief Security Officer, Chief Technology, and Vice President of Product Management during his nearly 12-year tenure. In 2020, Morey was elected to the Identity Defined Security Alliance (IDSA) Executive Advisory Board, assisting the corporate community with identity security best practices. He originally joined BeyondTrust in 2012 as a part of the acquisition of eEye Digital Security, where he served as a Product Owner and Solutions Engineer, since 2004. Prior to eEye, he was Beta Development Manager for Computer Associates, Inc. He began his career as Reliability and Maintainability Engineer for a government contractor building flight and training simulators. Morey earned a Bachelor of Science degree in Electrical Engineering from the State University of New York at Stony Brook.
James Maude is the Field Chief Technology Officer (FCTO) at BeyondTrust. With his broad experience in security research, both in academia and industry, James has spent the past decade analyzing cyber threats to identify attack vectors and trends in t
... read more
James Maude is the Field Chief Technology Officer (FCTO) at BeyondTrust. With his broad experience in security research, both in academia and industry, James has spent the past decade analyzing cyber threats to identify attack vectors and trends in the evolving security landscape. He is an active member of the security community and hosts Adventures of Alice and Bob, a podcast that shines a light on the people making a difference in security. As an expert voice on cybersecurity, he regularly presents at international events and hosts webinars to discuss threats and defense strategies.
James Maude is the Field Chief Technology Officer (FCTO) at BeyondTrust. With his broad experience in security research, both in academia and industry, James has spent the past decade analyzing cyber threats to identify attack vectors and trends in t
...
read more
James Maude
Field Chief Technology Officer
James Maude is the Field Chief Technology Officer (FCTO) at BeyondTrust. With his broad experience in security research, both in academia and industry, James has spent the past decade analyzing cyber threats to identify attack vectors and trends in the evolving security landscape. He is an active member of the security community and hosts Adventures of Alice and Bob, a podcast that shines a light on the people making a difference in security. As an expert voice on cybersecurity, he regularly presents at international events and hosts webinars to discuss threats and defense strategies.
Christopher L. Hills has more than 20 years’ experience in Identity Security as a Technical Director, Senior Solutions Architect, and Security Engineer operating in highly sensitive environments. Chris is a military veteran of the United States Navy
... read more
Christopher L. Hills has more than 20 years’ experience in Identity Security as a Technical Director, Senior Solutions Architect, and Security Engineer operating in highly sensitive environments. Chris is a military veteran of the United States Navy and started with BeyondTrust after his most recent role leading a Privileged Access Management (PAM) team as a Technical Director within a Fortune 500 organization. In his current position, he has responsibilities as a global Chief Security Strategist working with Customers, Marketing, Executives, Thought Leadership, Market Trends, and Corporate Influencer. Chris has held the title of Sr. Solution’s Architect, Deputy CTO, and Deputy CISO roles since starting with BeyondTrust. Chris is also co-author in the Cloud Attack Vectors book, a contributor in the New Privileged Attack Vectors book, and editor in previous books. Chris has been featured and writes for CXO, Dark Reading, and Computer Weekly to name a few. In his free time, Chris enjoys spending time with his family on the water boating, supporting his son’s college football career, going to the sand dunes offroading.
Christopher L. Hills has more than 20 years’ experience in Identity Security as a Technical Director, Senior Solutions Architect, and Security Engineer operating in highly sensitive environments. Chris is a military veteran of the United States Navy
...
read more
Christopher Hills
Chief Security Strategist
Christopher L. Hills has more than 20 years’ experience in Identity Security as a Technical Director, Senior Solutions Architect, and Security Engineer operating in highly sensitive environments. Chris is a military veteran of the United States Navy and started with BeyondTrust after his most recent role leading a Privileged Access Management (PAM) team as a Technical Director within a Fortune 500 organization. In his current position, he has responsibilities as a global Chief Security Strategist working with Customers, Marketing, Executives, Thought Leadership, Market Trends, and Corporate Influencer. Chris has held the title of Sr. Solution’s Architect, Deputy CTO, and Deputy CISO roles since starting with BeyondTrust. Chris is also co-author in the Cloud Attack Vectors book, a contributor in the New Privileged Attack Vectors book, and editor in previous books. Chris has been featured and writes for CXO, Dark Reading, and Computer Weekly to name a few. In his free time, Chris enjoys spending time with his family on the water boating, supporting his son’s college football career, going to the sand dunes offroading.