Common Vulnerabilities and Exposures (CVE)

CVE-2026-57990

Jul 26, 2026 17:22:14 UTC

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-62835

Jul 26, 2026 17:22:14 UTC

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVE-2026-58275

Jul 26, 2026 17:22:13 UTC

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58630

Jul 26, 2026 17:22:13 UTC

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62825

Jul 26, 2026 17:22:12 UTC

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-57106

Jul 26, 2026 17:22:12 UTC

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56191

Jul 26, 2026 17:22:11 UTC

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVE-2026-50517

Jul 26, 2026 17:22:11 UTC

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

CVE-2026-49159

Jul 26, 2026 17:22:10 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

CVE-2026-35425

Jul 26, 2026 17:22:09 UTC

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

CVE-2026-56171

Jul 26, 2026 17:22:09 UTC

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58529

Jul 26, 2026 17:22:08 UTC

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVE-2026-57989

Jul 26, 2026 17:22:08 UTC

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-62826

Jul 26, 2026 17:22:07 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55121

Jul 26, 2026 17:22:07 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.