Common Vulnerabilities and Exposures (CVE)

CVE-2026-58630

Sep 2, 2026 17:58:36 UTC

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62825

Sep 2, 2026 17:58:35 UTC

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-57106

Sep 2, 2026 17:58:35 UTC

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56191

Sep 2, 2026 17:58:34 UTC

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVE-2026-50517

Sep 2, 2026 17:58:34 UTC

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

CVE-2026-49159

Sep 2, 2026 17:58:33 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

CVE-2026-35425

Sep 2, 2026 17:58:33 UTC

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

CVE-2026-56171

Sep 2, 2026 17:58:32 UTC

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58529

Sep 2, 2026 17:58:31 UTC

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVE-2026-82661

Sep 2, 2026 17:58:31 UTC

Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF seque...

CVE-2026-62870

Sep 2, 2026 17:58:31 UTC

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

CVE-2023-50224

Sep 2, 2026 17:58:31 UTC

TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authe...

CVE-2026-66326

Sep 2, 2026 17:58:30 UTC

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-66325

Sep 2, 2026 17:58:30 UTC

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-66322

Sep 2, 2026 17:58:29 UTC

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.