Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MS:CVE-2026-26147

Azure Stack HCI Information Disclosure Vulnerability_MS:CVE-2026-26147

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-35430

Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability_MS:CVE-2026-35430

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges ...

N/A N/A MSCVE
NONE MS:CVE-2026-45659

Microsoft SharePoint Remote Code Execution Vulnerability_MS:CVE-2026-45659

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-40412

Azure Orbital Spatio Remote Code Execution Vulnerability_MS:CVE-2026-40412

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-41090

Microsoft Copilot Tampering Vulnerability_MS:CVE-2026-41090

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform...

N/A N/A MSCVE
NONE MS:CVE-2026-42901

Microsoft Entra ID Elevation of Privilege Vulnerability_MS:CVE-2026-42901

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-42827

M365 Copilot Information Disclosure Vulnerability_MS:CVE-2026-42827

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose inf...

N/A N/A MSCVE
NONE MS:CVE-2026-23663

Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability_MS:CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-23652

Microsoft Power Pages Remote Code Execution Vulnerability_MS:CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to exe...

N/A N/A MSCVE
NONE MS:CVE-2026-33843

Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability_MS:CVE-2026-33843

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privile...

N/A N/A MSCVE