Common Vulnerabilities and Exposures (CVE)

CVE-2026-56159

Jul 27, 2026 23:52:21 UTC

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-50343

Jul 27, 2026 23:52:21 UTC

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50697

Jul 27, 2026 23:52:20 UTC

Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50333

Jul 27, 2026 23:52:20 UTC

Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-62835

Jul 27, 2026 23:52:19 UTC

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVE-2026-58275

Jul 27, 2026 23:52:19 UTC

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58630

Jul 27, 2026 23:52:18 UTC

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62825

Jul 27, 2026 23:52:17 UTC

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-57106

Jul 27, 2026 23:52:17 UTC

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56191

Jul 27, 2026 23:52:16 UTC

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVE-2026-50517

Jul 27, 2026 23:52:15 UTC

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

CVE-2026-49159

Jul 27, 2026 23:52:15 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

CVE-2026-35425

Jul 27, 2026 23:52:14 UTC

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

CVE-2026-56171

Jul 27, 2026 23:52:13 UTC

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58529

Jul 27, 2026 23:52:13 UTC

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.