Common Vulnerabilities and Exposures (CVE)

CVE-2026-65768

Aug 16, 2026 17:16:33 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

CVE-2026-65767

Aug 16, 2026 17:16:33 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

CVE-2026-65769

Aug 16, 2026 17:16:32 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

CVE-2026-69414

Aug 16, 2026 17:16:32 UTC

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this ...

CVE-2026-50523

Aug 16, 2026 17:16:31 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

CVE-2026-70338

Aug 16, 2026 17:16:31 UTC

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-70337

Aug 16, 2026 17:16:30 UTC

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

CVE-2026-59119

Aug 16, 2026 17:16:29 UTC

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

CVE-2026-58612

Aug 16, 2026 17:16:29 UTC

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

CVE-2026-62869

Aug 16, 2026 17:16:29 UTC

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

CVE-2026-68823

Aug 16, 2026 17:16:28 UTC

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

CVE-2026-49163

Aug 16, 2026 17:16:28 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

CVE-2026-65667

Aug 16, 2026 17:16:27 UTC

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56162

Aug 16, 2026 17:16:26 UTC

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50516

Aug 16, 2026 17:16:26 UTC

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.