Common Vulnerabilities and Exposures (CVE)

CVE-2026-70331

Aug 29, 2026 16:21:04 UTC

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-69836

Aug 29, 2026 16:21:04 UTC

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

CVE-2026-69851

Aug 29, 2026 16:21:03 UTC

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

CVE-2026-69519

Aug 29, 2026 16:21:03 UTC

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

CVE-2026-68789

Aug 29, 2026 16:21:02 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

CVE-2026-65801

Aug 29, 2026 16:21:02 UTC

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62834

Aug 29, 2026 16:21:01 UTC

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-72970

Aug 29, 2026 16:21:01 UTC

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-62873

Aug 29, 2026 16:21:00 UTC

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-63508

Aug 29, 2026 16:21:00 UTC

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50481

Aug 29, 2026 16:20:59 UTC

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

CVE-2026-62918

Aug 29, 2026 16:20:59 UTC

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-59115

Aug 29, 2026 16:20:58 UTC

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

CVE-2026-50515

Aug 29, 2026 16:20:58 UTC

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

CVE-2026-65668

Aug 29, 2026 16:20:57 UTC

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.