Common Vulnerabilities and Exposures (CVE)

CVE-2026-77903

Sep 19, 2026 03:56:37 UTC

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-83318

Sep 19, 2026 03:56:36 UTC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged att...

CVE-2026-85885

Sep 19, 2026 03:56:35 UTC

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

CVE-2026-83944

Sep 19, 2026 03:56:34 UTC

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-87701

Sep 19, 2026 03:56:33 UTC

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

CVE-2026-70200

Sep 19, 2026 03:56:32 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62874

Sep 19, 2026 03:56:31 UTC

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-85889

Sep 19, 2026 03:56:30 UTC

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-85917

Sep 19, 2026 03:56:28 UTC

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-85878

Sep 19, 2026 03:56:27 UTC

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

CVE-2026-15815

Sep 19, 2026 03:56:26 UTC

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files...

CVE-2026-69843

Sep 19, 2026 03:56:25 UTC

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-39682

Sep 19, 2026 03:56:24 UTC

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA recor...

CVE-2026-93375

Sep 19, 2026 03:56:23 UTC

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVE-2026-53266

Sep 19, 2026 03:56:22 UTC

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is inte...