Common Vulnerabilities and Exposures (CVE)

CVE-2025-71178

Jan 26, 2026 17:55:02 UTC

Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During installation, the installer runs with elevated privileges and loads Windows DLLs using an uncontrolled search path, which c...

CVE-2026-0925

Jan 26, 2026 17:51:34 UTC

Tanium addressed an improper input validation vulnerability in Discover.

CVE-2026-21509

Jan 26, 2026 17:50:44 UTC

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-21264

Jan 26, 2026 17:50:44 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-21521

Jan 26, 2026 17:50:43 UTC

Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-21227

Jan 26, 2026 17:50:43 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-24307

Jan 26, 2026 17:50:42 UTC

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-24305

Jan 26, 2026 17:50:41 UTC

Azure Entra ID Elevation of Privilege Vulnerability

CVE-2026-21524

Jan 26, 2026 17:50:41 UTC

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-24306

Jan 26, 2026 17:50:40 UTC

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-24304

Jan 26, 2026 17:50:40 UTC

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-21520

Jan 26, 2026 17:50:39 UTC

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

CVE-2026-21223

Jan 26, 2026 17:50:38 UTC

Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdEl...

CVE-2026-21226

Jan 26, 2026 17:50:38 UTC

Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

CVE-2026-20941

Jan 26, 2026 17:50:37 UTC

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.