Common Vulnerabilities and Exposures (CVE)

CVE-2025-7195

Feb 13, 2026 23:41:16 UTC

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/pass...

CVE-2025-55338

Feb 13, 2026 23:13:12 UTC

Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2025-59213

Feb 13, 2026 23:13:11 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2025-60711

Feb 13, 2026 23:13:10 UTC

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2025-59501

Feb 13, 2026 23:13:10 UTC

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

CVE-2025-59500

Feb 13, 2026 23:13:09 UTC

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

CVE-2025-59503

Feb 13, 2026 23:13:09 UTC

Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-59273

Feb 13, 2026 23:13:08 UTC

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-59286

Feb 13, 2026 23:13:07 UTC

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2025-55321

Feb 13, 2026 23:13:07 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-59272

Feb 13, 2026 23:13:06 UTC

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

CVE-2025-59271

Feb 13, 2026 23:13:06 UTC

Redis Enterprise Elevation of Privilege Vulnerability

CVE-2025-59252

Feb 13, 2026 23:13:05 UTC

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2025-59247

Feb 13, 2026 23:13:05 UTC

Azure PlayFab Elevation of Privilege Vulnerability

CVE-2025-59246

Feb 13, 2026 23:13:04 UTC

Azure Entra ID Elevation of Privilege Vulnerability