Common Vulnerabilities and Exposures (CVE)

CVE-2026-23662

Mar 27, 2026 22:33:12 UTC

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-23661

Mar 27, 2026 22:33:11 UTC

Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-23654

Mar 27, 2026 22:33:11 UTC

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

CVE-2026-32194

Mar 27, 2026 22:33:10 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

CVE-2026-26136

Mar 27, 2026 22:33:10 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-24299

Mar 27, 2026 22:33:09 UTC

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-23659

Mar 27, 2026 22:33:09 UTC

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

CVE-2026-26120

Mar 27, 2026 22:33:08 UTC

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

CVE-2026-23658

Mar 27, 2026 22:33:08 UTC

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-32191

Mar 27, 2026 22:33:07 UTC

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

CVE-2026-26138

Mar 27, 2026 22:33:06 UTC

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-26139

Mar 27, 2026 22:33:06 UTC

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-32169

Mar 27, 2026 22:33:05 UTC

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-26148

Mar 27, 2026 22:33:05 UTC

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

CVE-2026-26122

Mar 27, 2026 22:33:04 UTC

Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.