Common Vulnerabilities and Exposures (CVE)

CVE-2026-40404

Aug 13, 2026 20:52:16 UTC

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-40409

Aug 13, 2026 20:52:16 UTC

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-48584

Aug 13, 2026 20:52:15 UTC

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

CVE-2026-47647

Aug 13, 2026 20:52:15 UTC

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

CVE-2026-54130

Aug 13, 2026 20:52:14 UTC

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-42895

Aug 13, 2026 20:52:14 UTC

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

CVE-2026-45480

Aug 13, 2026 20:52:13 UTC

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-32174

Aug 13, 2026 20:52:12 UTC

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-32208

Aug 13, 2026 20:52:12 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.

CVE-2026-47633

Aug 13, 2026 20:52:11 UTC

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

CVE-2026-47655

Aug 13, 2026 20:52:11 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

CVE-2026-47644

Aug 13, 2026 20:52:10 UTC

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

CVE-2026-45483

Aug 13, 2026 20:52:09 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

CVE-2026-45485

Aug 13, 2026 20:52:09 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-45486

Aug 13, 2026 20:52:08 UTC

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.