Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 MS:CVE-2026-11092

Chromium: CVE-2026-11092 Insufficient policy enforcement in DevTools_MS:CVE-2026-11092

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-11039

Chromium: CVE-2026-11039 Uninitialized Use in Skia_MS:CVE-2026-11039

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 5.7 MS:CVE-2026-11199

Chromium: CVE-2026-11199 Insufficient validation of untrusted input in WebRTC_MS:CVE-2026-11199

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.8 MS:CVE-2026-11147

Chromium: CVE-2026-11147 Use after free in WebML_MS:CVE-2026-11147

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-47655

Microsoft Graph Information Disclosure Vulnerability_MS:CVE-2026-47655

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-42824

M365 Copilot Information Disclosure Vulnerability_MS:CVE-2026-42824

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose inf...

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-47644

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability_MS:CVE-2026-47644

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unaut...

N/A N/A MSCVE
CRITICAL 10 MS:CVE-2026-48567

Azure HorizonDB Elevation of Privilege Vulnerability_MS:CVE-2026-48567

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
HIGH 7.7 MS:CVE-2026-45497

Microsoft M365 Copilot Remote Code Execution Vulnerability_MS:CVE-2026-45497

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute c...

N/A N/A MSCVE
CRITICAL 9.1 MS:CVE-2026-48579

Microsoft Exchange Online Information Disclosure Vulnerability_MS:CVE-2026-48579

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE