Common Vulnerabilities and Exposures (CVE)

CVE-2026-82461

Aug 29, 2026 16:35:25 UTC

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypas...

CVE-2026-82460

Aug 29, 2026 16:35:24 UTC

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, o...

CVE-2026-68821

Aug 29, 2026 16:25:16 UTC

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-70337

Aug 29, 2026 16:25:16 UTC

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

CVE-2026-70329

Aug 29, 2026 16:25:15 UTC

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-65813

Aug 29, 2026 16:25:15 UTC

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-69855

Aug 29, 2026 16:25:14 UTC

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

CVE-2026-69543

Aug 29, 2026 16:25:14 UTC

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

CVE-2026-69558

Aug 29, 2026 16:25:13 UTC

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

CVE-2026-69555

Aug 29, 2026 16:25:13 UTC

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69400

Aug 29, 2026 16:25:12 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69502

Aug 29, 2026 16:25:11 UTC

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-69419

Aug 29, 2026 16:25:11 UTC

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

CVE-2026-68782

Aug 29, 2026 16:25:10 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

CVE-2026-66800

Aug 29, 2026 16:25:10 UTC

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.