Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 MS:CVE-2026-5947

SIG(0) validation during query flood may lead to undefined behavior_MS:CVE-2026-5947

{“lastseen”:”2026-05-23T07:16:22″,”description”:””,”published”:”2026-05-23T08:01:...

N/A N/A MSCVE
NONE MS:CVE-2026-47280

Azure Resource Manager Elevation of Privilege Vulnerability_MS:CVE-2026-47280

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-26147

Azure Stack HCI Information Disclosure Vulnerability_MS:CVE-2026-26147

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-35430

Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability_MS:CVE-2026-35430

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges ...

N/A N/A MSCVE
NONE MS:CVE-2026-45659

Microsoft SharePoint Remote Code Execution Vulnerability_MS:CVE-2026-45659

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-40412

Azure Orbital Spatio Remote Code Execution Vulnerability_MS:CVE-2026-40412

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-42901

Microsoft Entra ID Elevation of Privilege Vulnerability_MS:CVE-2026-42901

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-41090

Microsoft Copilot Tampering Vulnerability_MS:CVE-2026-41090

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform...

N/A N/A MSCVE
NONE MS:CVE-2026-42827

M365 Copilot Information Disclosure Vulnerability_MS:CVE-2026-42827

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose inf...

N/A N/A MSCVE
NONE MS:CVE-2026-23663

Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability_MS:CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE