Common Vulnerabilities and Exposures (CVE)

CVE-2026-58612

Sep 3, 2026 15:28:52 UTC

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

CVE-2026-49179

Sep 3, 2026 15:28:51 UTC

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

CVE-2026-54984

Sep 3, 2026 15:28:51 UTC

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

CVE-2026-54113

Sep 3, 2026 15:28:50 UTC

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

CVE-2026-40375

Sep 3, 2026 15:28:50 UTC

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

CVE-2026-70331

Sep 3, 2026 15:28:49 UTC

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-69836

Sep 3, 2026 15:28:48 UTC

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

CVE-2026-69851

Sep 3, 2026 15:28:48 UTC

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

CVE-2026-69519

Sep 3, 2026 15:28:47 UTC

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

CVE-2026-68789

Sep 3, 2026 15:28:47 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

CVE-2026-65801

Sep 3, 2026 15:28:46 UTC

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62834

Sep 3, 2026 15:28:45 UTC

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-72970

Sep 3, 2026 15:28:45 UTC

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-62873

Sep 3, 2026 15:28:44 UTC

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-63508

Sep 3, 2026 15:28:44 UTC

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.