Common Vulnerabilities and Exposures (CVE)

CVE-2026-56161

Aug 18, 2026 22:28:43 UTC

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CVE-2026-62830

Aug 18, 2026 22:28:42 UTC

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

CVE-2026-62917

Aug 18, 2026 22:28:41 UTC

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-62839

Aug 18, 2026 22:28:41 UTC

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-58639

Aug 18, 2026 22:28:40 UTC

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-65767

Aug 18, 2026 22:28:40 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

CVE-2026-62898

Aug 18, 2026 22:28:39 UTC

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

CVE-2026-62738

Aug 18, 2026 22:28:39 UTC

Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

CVE-2026-71331

Aug 18, 2026 22:28:38 UTC

Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

CVE-2026-70354

Aug 18, 2026 22:28:37 UTC

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

CVE-2026-63522

Aug 18, 2026 22:28:37 UTC

Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

CVE-2026-70332

Aug 18, 2026 22:28:36 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-70337

Aug 18, 2026 22:28:36 UTC

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

CVE-2026-70326

Aug 18, 2026 22:28:35 UTC

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-70306

Aug 18, 2026 22:28:35 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.