Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 MS:CVE-2026-6919

Chromium: CVE-2026-6919 Use after free in DevTools_MS:CVE-2026-6919

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.3 MS:CVE-2026-6921

Chromium: CVE-2026-6921 Race in GPU_MS:CVE-2026-6921

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 2.1 MS:CVE-2026-5958

Race Condition in GNU Sed_MS:CVE-2026-5958

{“lastseen”:”2026-04-24T07:13:17″,”description”:””,”published”:”2026-04-22T08:01:...

N/A N/A MSCVE
CRITICAL 9.3 MS:CVE-2026-32210

Microsoft Dynamics 365 (online) Spoofing Vulnerability_MS:CVE-2026-32210

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

N/A N/A MSCVE
CRITICAL 9.6 MS:CVE-2026-24303

Microsoft Partner Center Elevation of Privilege Vulnerability_MS:CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

N/A N/A MSCVE
CRITICAL 10 MS:CVE-2026-33819

Microsoft Bing Remote Code Execution Vulnerability_MS:CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-21515

Azure IoT Central Elevation of Privilege Vulnerability_MS:CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

N/A N/A MSCVE
CRITICAL 10 MS:CVE-2026-35431

Microsoft Entra ID Entitlement Management Spoofing Vulnerability_MS:CVE-2026-35431

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

N/A N/A MSCVE
HIGH 8.6 MS:CVE-2026-26150

Microsoft Purview eDiscovery Elevation of Privilege Vulnerability_MS:CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
HIGH 8 MS:CVE-2026-32172

Microsoft Power Apps Remote Code Execution Vulnerability_MS:CVE-2026-32172

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE