IT
58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.472 CVE

Microsoft vulnerabilities
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-85889 CRIT 10.0 microsoft azure_ai_foundry Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. 0.7% —
CVE-2026-83944 CRIT 10.0 microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.4% —
CVE-2026-70200 CRIT 10.0 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.6% —
CVE-2026-69865 CRIT 10.0 microsoft azure_container_registry Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69843 CRIT 10.0 microsoft fabric Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-69836 CRIT 10.0 microsoft entra_id Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. 1.5% —
CVE-2026-69555 CRIT 10.0 microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69502 CRIT 10.0 microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-69399 CRIT 10.0 microsoft azure_arc Azure Arc Elevation of Privilege Vulnerability 0.5% —
CVE-2026-66803 CRIT 10.0 microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. 0.9% —
CVE-2026-65816 CRIT 10.0 microsoft azure_web_apps Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 1.0% —
CVE-2026-65801 CRIT 10.0 microsoft exchange_online Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-65770 CRIT 10.0 microsoft azure_managed_instance_for_apache_cassandra Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. 1.1% —
CVE-2026-65667 CRIT 10.0 microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-63508 CRIT 10.0 microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-62825 CRIT 10.0 microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-58630 CRIT 10.0 microsoft azure_app_service_for_linux Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-58275 CRIT 10.0 microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-57106 CRIT 10.0 microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-56191 CRIT 10.0 microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. 0.9% —
CVE-2026-56163 CRIT 10.0 microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-56162 CRIT 10.0 microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-48567 CRIT 10.0 microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-47280 CRIT 10.0 microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-45480 CRIT 10.0 microsoft azure_active_directory Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. 0.9% —