Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MS:CVE-2026-41090

Microsoft Copilot Tampering Vulnerability_MS:CVE-2026-41090

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform...

N/A N/A MSCVE
NONE MS:CVE-2026-42901

Microsoft Entra ID Elevation of Privilege Vulnerability_MS:CVE-2026-42901

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-42827

M365 Copilot Information Disclosure Vulnerability_MS:CVE-2026-42827

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose inf...

N/A N/A MSCVE
NONE MS:CVE-2026-23663

Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability_MS:CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-33843

Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability_MS:CVE-2026-33843

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privile...

N/A N/A MSCVE
NONE MS:CVE-2026-23652

Microsoft Power Pages Remote Code Execution Vulnerability_MS:CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to exe...

N/A N/A MSCVE
NONE MS:CVE-2026-40411

Azure Virtual Network Gateway Remote Code Execution Vulnerability_MS:CVE-2026-40411

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-41104

Microsoft Planetary Computer Pro Information Disclosure Vulnerability_MS:CVE-2026-41104

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-8521

Chromium: CVE-2026-8521 Use after free in Tab Groups_MS:CVE-2026-8521

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.3 MS:CVE-2026-8520

Chromium: CVE-2026-8520 Race in Payments_MS:CVE-2026-8520

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE