Common Vulnerabilities and Exposures (CVE)

CVE-2026-62747

Aug 21, 2026 23:10:14 UTC

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69855

Aug 21, 2026 23:10:13 UTC

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

CVE-2026-69543

Aug 21, 2026 23:10:13 UTC

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

CVE-2026-69558

Aug 21, 2026 23:10:12 UTC

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

CVE-2026-69555

Aug 21, 2026 23:10:12 UTC

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69400

Aug 21, 2026 23:10:11 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69502

Aug 21, 2026 23:10:11 UTC

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69419

Aug 21, 2026 23:10:10 UTC

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

CVE-2026-68782

Aug 21, 2026 23:10:10 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

CVE-2026-66800

Aug 21, 2026 23:10:09 UTC

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

CVE-2026-66309

Aug 21, 2026 23:10:09 UTC

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

CVE-2026-65816

Aug 21, 2026 23:10:08 UTC

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-63509

Aug 21, 2026 23:10:07 UTC

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

CVE-2026-65770

Aug 21, 2026 23:10:07 UTC

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

CVE-2026-62869

Aug 21, 2026 23:10:06 UTC

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.