Microsoft Microsoft Makers of the Windows Operating System and hundreds of products that run on it.

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Microsoft product.

RSS Feeds for Microsoft security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Microsoft products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Microsoft Sorted by Most Security Vulnerabilities since 2018

Microsoft Windows 105237 vulnerabilities

Microsoft Windows Server 20194976 vulnerabilities

Microsoft Windows Server 20164881 vulnerabilities

Microsoft Windows Server 20123685 vulnerabilities

Microsoft Windows Server 20223335 vulnerabilities

Microsoft Windows Server 20082820 vulnerabilities

Microsoft Windows 112283 vulnerabilities

Microsoft Windows 11 24h21929 vulnerabilities

Microsoft Windows Server 20251918 vulnerabilities

Microsoft Windows Server 2012 R21859 vulnerabilities

Microsoft Windows 11 23h21852 vulnerabilities

Microsoft Windows 71811 vulnerabilities

Microsoft Windows 8.11715 vulnerabilities

Microsoft Windows 10 15071679 vulnerabilities

Microsoft Windows Rt 8 11592 vulnerabilities

Microsoft Windows Server 23h21431 vulnerabilities

Microsoft Windows Server 2008 R21100 vulnerabilities

Microsoft Windows 11 25h21091 vulnerabilities

Microsoft Windows 11 26h1938 vulnerabilities

Microsoft Windows932 vulnerabilities

Microsoft 365 Apps663 vulnerabilities

Microsoft Windows Server655 vulnerabilities

Microsoft Office597 vulnerabilities

Microsoft Internet Explorer (IE)528 vulnerabilities
Popular web browser for windows

Microsoft Windows 10 1909520 vulnerabilities

Microsoft Sharepoint Server519 vulnerabilities

Microsoft Windows Server 2004434 vulnerabilities

Microsoft Edge Browser421 vulnerabilities
Web Browser based on Chromium

Microsoft Office 2019404 vulnerabilities

Microsoft Office 2021401 vulnerabilities

Microsoft Office 2024398 vulnerabilities

Microsoft Windows Server 20h2397 vulnerabilities

Microsoft Windows Vista382 vulnerabilities

Microsoft Windows Server 1909344 vulnerabilities

Microsoft Office Macos 2021335 vulnerabilities

Microsoft Office Macos 2024332 vulnerabilities

Microsoft Windows XP326 vulnerabilities

Microsoft Windows Server 1903317 vulnerabilities

Microsoft Edge Chromium303 vulnerabilities

Microsoft Windows 10 1803279 vulnerabilities

Microsoft Windows 10 21h1267 vulnerabilities

Microsoft Windows Server 2003262 vulnerabilities

Microsoft Excel194 vulnerabilities
Spreadsheet Software

Microsoft Office 365180 vulnerabilities

Microsoft Windows Server 1803171 vulnerabilities

Microsoft Windows 2003 Server162 vulnerabilities

Microsoft Excel 2016154 vulnerabilities

Microsoft Visual Studio 2022150 vulnerabilities

Microsoft Net142 vulnerabilities

Microsoft Sql Server 2019141 vulnerabilities

Microsoft Office Online Server135 vulnerabilities

Microsoft Exchange Server132 vulnerabilities

Microsoft Visual Studio 2019125 vulnerabilities

Microsoft Office 2016114 vulnerabilities

Microsoft Sql Server 2022113 vulnerabilities

Microsoft Windows 2000112 vulnerabilities

Microsoft Windows 11 2h2110 vulnerabilities

Microsoft SQL Server106 vulnerabilities
Database Server

Microsoft Word104 vulnerabilities

Microsoft Dynamics 365103 vulnerabilities

Microsoft Sql Server 201799 vulnerabilities

Microsoft Sql Server 201697 vulnerabilities

Microsoft Visual Studio 201797 vulnerabilities

Microsoft Visual Studio96 vulnerabilities
Developer IDE

Microsoft Office 365 Proplus87 vulnerabilities

Microsoft Visual Studio Code87 vulnerabilities
VSCode Developer IDE

Microsoft Outlook86 vulnerabilities

Microsoft Word 201662 vulnerabilities

Microsoft Windows 861 vulnerabilities

Microsoft Windows Nt57 vulnerabilities

Microsoft Office Web Apps55 vulnerabilities

Microsoft Azure Site Recovery53 vulnerabilities

Microsoft Powershell51 vulnerabilities

Microsoft Windows Rt46 vulnerabilities

Microsoft .NET Framework45 vulnerabilities

Microsoft Exchange Server 201642 vulnerabilities

Microsoft Http Server41 vulnerabilities

Microsoft Windows 10 170940 vulnerabilities

Microsoft Azure Devops Server40 vulnerabilities

Microsoft 39 vulnerabilities

Microsoft ASP.NET Core37 vulnerabilities

Microsoft Mysql36 vulnerabilities

Microsoft .NET Core35 vulnerabilities

Microsoft Remote Desktop35 vulnerabilities

Microsoft Exchange Server 201935 vulnerabilities

Microsoft Excel Viewer34 vulnerabilities

Microsoft Visual Studio 202633 vulnerabilities

Microsoft Teams33 vulnerabilities

Microsoft Windows 10 170331 vulnerabilities

Microsoft Exchange Server Se30 vulnerabilities

Recent Microsoft Security Advisories

Advisory Title Published
CVE-2026-69851 CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability August 20, 2026
CVE-2026-62834 CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability August 20, 2026
CVE-2026-55015 CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability August 20, 2026
CVE-2026-69855 CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability August 20, 2026
CVE-2026-68789 CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability August 20, 2026
CVE-2026-69836 CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability August 20, 2026
CVE-2026-65770 CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability August 20, 2026
CVE-2026-70105 CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability August 20, 2026
CVE-2026-69519 CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability August 20, 2026
CVE-2026-65801 CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability August 20, 2026

Known Exploited Microsoft Vulnerabilities

The following Microsoft vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
CVE-2026-33824 Exploit Probability: 55.9%
August 18, 2026
Microsoft SharePoint Weak Authentication Vulnerability Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-55040 Exploit Probability: 1.3%
August 18, 2026
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-68820
August 11, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
CVE-2026-50522 Exploit Probability: 57.1%
July 22, 2026
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2026-58644
July 16, 2026
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56164 Exploit Probability: 18.4%
July 14, 2026
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerabil Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-56155 Exploit Probability: 2.3%
July 14, 2026
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-45659 Exploit Probability: 9.1%
July 1, 2026
Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2010-0249 Exploit Probability: 91.9%
May 20, 2026
Microsoft Windows Buffer Overflow Vulnerability Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
CVE-2008-4250 Exploit Probability: 98.8%
May 20, 2026
Microsoft Defender Denial of Service Vulnerability Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
CVE-2026-45498 Exploit Probability: 63.1%
May 20, 2026
Microsoft DirectX NULL Byte Overwrite Vulnerability Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
CVE-2009-1537 Exploit Probability: 51.2%
May 20, 2026
Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2010-0806 Exploit Probability: 82.2%
May 20, 2026
Microsoft Defender Link Following Vulnerability Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2026-41091 Exploit Probability: 9.6%
May 20, 2026
Microsoft Exchange Server Cross-Site Scripting Vulnerability Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
CVE-2026-42897 Exploit Probability: 5.6%
May 15, 2026
Microsoft Windows Protection Mechanism Failure Vulnerability Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32202 Exploit Probability: 63.7%
April 28, 2026
Microsoft Defender Insufficient Granularity of Access Control Vulnerability Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CVE-2026-33825 Exploit Probability: 6.7%
April 22, 2026
Microsoft Office Remote Code Execution Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
CVE-2009-0238 Exploit Probability: 43.1%
April 14, 2026
Microsoft SharePoint Server Improper Input Validation Vulnerability Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32201 Exploit Probability: 21.5%
April 14, 2026
Microsoft Windows Out-of-Bounds Read Vulnerability Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CVE-2023-36424 Exploit Probability: 12.2%
April 13, 2026

Of the known exploited vulnerabilities above, 5 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 7 known exploited Microsoft vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest Microsoft Vulnerabilities

Based on the current exploit probability, these Microsoft vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2021-34473 100.0% Microsoft Exchange Server Remote Code Execution Vulnerability
2 CVE-2019-0708 100.0% "BlueKeep" Microsoft Windows Remote Desktop Remote Code Execution Vulnerability
3 CVE-2015-1635 100.0% Microsoft HTTP.sys Remote Code Execution Vulnerability
4 CVE-2021-26855 100.0% Microsoft OWA Exchange Control Panel (ECP) Exploit Chain
5 CVE-2021-34523 100.0% Microsoft Exchange Server Privilege Escalation Vulnerability
6 CVE-2025-53770 100.0% Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
7 CVE-2022-41082 100.0% Microsoft Exchange Server Remote Code Execution Vulnerability
8 CVE-2012-0158 100.0% Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
9 CVE-2020-0688 100.0% Microsoft Exchange Server Key Validation Vulnerability
10 CVE-2022-41040 100.0% Microsoft Exchange Server Server-Side Request Forgery Vulnerability

By the Year

In 2026 there have been 5515 vulnerabilities in Microsoft with an average score of 7.3 out of ten. Last year, in 2025 Microsoft had 2759 security vulnerabilities published. That is, 2756 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.08.




Year Vulnerabilities Average Score
2026 5515 7.30
2025 2759 7.23
2024 2182 7.39
2023 1695 7.21
2022 1389 7.43
2021 1153 7.44
2020 1253 7.19
2019 831 7.08
2018 661 7.03

It may take a day or so for new Microsoft vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-62316 Aug 21, 2026
UFO Linux MCP Server DNS Rebinding via Unvalidated Headers (v<3.0.8) Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8.
CVE-2026-69502 Aug 21, 2026
Aug 2026: Azure SQL Database Elevation of Privilege Vulnerability Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Azure Sql Database
CVE-2026-69855 Aug 20, 2026
Aug 2026: Microsoft Copilot in Azure Information Disclosure Vulnerability Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
Microsoft Copilot In Azure
CVE-2026-69558 Aug 20, 2026
Aug 2026: Microsoft Partner Center Information Disclosure Vulnerability Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
Partner Center
CVE-2026-69543 Aug 20, 2026
Aug 2026: Azure Virtual Machines Elevation of Privilege Vulnerability Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
Azure Virtual Machines
CVE-2026-69555 Aug 20, 2026
Aug 2026: Azure Arc Elevation of Privilege Vulnerability Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Arc
CVE-2026-69400 Aug 20, 2026
Aug 2026: Azure Logic Apps Elevation of Privilege Vulnerability Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Azure Logic Apps
CVE-2026-69419 Aug 20, 2026
Aug 2026: Azure Data Manager for Energy Remote Code Execution Vulnerability Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
Azure Data Manager For Energy
CVE-2026-68782 Aug 20, 2026
Aug 2026: Azure SQL Database Elevation of Privilege Vulnerability Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Azure Sql Database
CVE-2026-66800 Aug 20, 2026
Aug 2026: Azure Data Factory Information Disclosure Vulnerability Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
Azure Data Factory
CVE-2026-66309 Aug 20, 2026
Aug 2026: Azure SQL Database Elevation of Privilege Vulnerability Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Azure Sql Database
CVE-2026-65816 Aug 20, 2026
Aug 2026: Azure Arc Elevation of Privilege Vulnerability Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Web Apps
CVE-2026-63509 Aug 20, 2026
Aug 2026: Microsoft Fabric Elevation of Privilege Vulnerability Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Microsoft Fabric
CVE-2026-65770 Aug 20, 2026
Aug 2026: Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
Azure Managed Instance Apache Cassandra
Cassandra
CVE-2026-70105 Aug 20, 2026
Aug 2026: Microsoft Word Information Disclosure Vulnerability Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Office 2019
365 Apps
Office Macos 2021
And others...
CVE-2026-55013 Aug 20, 2026
Aug 2026: Windows Remote Help Defense Spoofing Vulnerability Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
Windows Remote Help
CVE-2026-55015 Aug 20, 2026
Aug 2026: Microsoft Remote Help Denial of Service Vulnerability Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
Windows Remote Help
CVE-2026-69836 Aug 20, 2026
Aug 2026: Microsoft Entra ID Remote Code Execution Vulnerability Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Microsoft Entra Id
CVE-2026-69851 Aug 20, 2026
Aug 2026: Microsoft Entra ID Elevation of Privilege Vulnerability Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Microsoft Entra Id
CVE-2026-69519 Aug 20, 2026
Aug 2026: Azure Stack HCI Information Disclosure Vulnerability Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
Azure Stack Hci
CVE-2026-68789 Aug 20, 2026
Aug 2026: Azure SQL Database Elevation of Privilege Vulnerability Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Azure Sql Database
CVE-2026-65801 Aug 20, 2026
Aug 2026: Microsoft Exchange Online Elevation of Privilege Vulnerability Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Exchange Online
CVE-2026-62834 Aug 20, 2026
Aug 2026: Azure Data Factory Elevation of Privilege Vulnerability Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
Azure Data Factory
CVE-2026-69550 Aug 19, 2026
Aug 2026: Windows App for Mac Information Disclosure Vulnerability Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Windows App For Mac
CVE-2026-62727 Aug 19, 2026
Aug 2026: Windows Telephony Service Elevation of Privilege Vulnerability Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Windows 10
Windows Server 2019
Windows Server 2022
And others...
CVE-2026-24301 Aug 18, 2026
Aug 2026: Microsoft Copilot Information Disclosure Vulnerability Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Copilot Web
CVE-2026-73851 Aug 17, 2026
Aug 2026: Kiota: Path traversal in generated plugin manifest static_template.file reference (percent Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0.
CVE-2026-69414 Aug 14, 2026
Aug 2026: Microsoft Defender Elevation of Privilege Vulnerability Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
Malware Protection Engine
CVE-2026-50523 Aug 14, 2026
Aug 2026: Microsoft PowerShell Remote Code Execution Vulnerability Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
Powershell
CVE-2026-72970 Aug 14, 2026
Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
CVE-2026-73299 Aug 12, 2026
Aug 2026: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunj Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.
CVE-2026-73298 Aug 12, 2026
Aug 2026: Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/write The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was identified in the Container Migration Solution Accelerator, specifically an authenticated IDOR (Insecure Direct Object Reference) that allows users to read, write, and delete processes belonging to other authenticated users. The issue affects multiple API endpoints, where ownership checks are missing, enabling unauthorized access and modification of migration data across users within the same organization. The vulnerability is present in both process and file management APIs, and the application relies on Entra ID authentication but lacks proper authorization controls between users. Authenticated users are able to access, modify, and delete processes and files belonging to other users without proper authorization checks.
CVE-2026-73297 Aug 12, 2026
Aug 2026: Microsoft UFO: IPv6 transition address bypass of SSRF guard in URL validation Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4 destinations, allowing an unauthenticated remote attacker who can influence URLs processed by validate_url to bypass the SSRF guard and reach cloud metadata, internal services, or localhost. This issue is fixed in version 3.0.8.
CVE-2026-73296 Aug 12, 2026
Aug 2026: Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.
CVE-2026-19560 Aug 11, 2026
Google Chrome <151.0.7922.137 Use-After-Free in Blink RCE Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-19558 Aug 11, 2026
Chrome Extension Use-After-Free <151.0.7922.137 Exec Arbitrary Code Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
CVE-2026-19559 Aug 11, 2026
Use-After-Free in Chrome HTML Engine (before 151.0.7922.137) Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-19556 Aug 11, 2026
Use-after-free in V8 (Chrome <151.0.7922.137) RCE in sandbox Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-19557 Aug 11, 2026
UAF in TabStrip (Chrome <151.0.7922.137) enables sandbox escape Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-70339 Aug 11, 2026
Aug 2026: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
CVE-2026-65680 Aug 11, 2026
Aug 2026: Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Onedrive For Macos
CVE-2026-62869 Aug 11, 2026
Aug 2026: Azure Entra ID Spoofing Vulnerability Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
Microsoft Entra Id
CVE-2026-50516 Aug 11, 2026
Aug 2026: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
CVE-2026-62917 Aug 11, 2026
Aug 2026: Microsoft SharePoint Server Spoofing Vulnerability Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server 2016
Sharepoint Server 2019
Sharepoint Server
And others...
CVE-2026-62839 Aug 11, 2026
Aug 2026: Microsoft SharePoint Server Spoofing Vulnerability Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server 2016
Sharepoint Server 2019
Sharepoint Server
And others...
CVE-2026-58639 Aug 11, 2026
Aug 2026: Microsoft SharePoint Server Spoofing Vulnerability Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Sharepoint Server 2016
Sharepoint Server 2019
Sharepoint Server
And others...
CVE-2026-65767 Aug 11, 2026
Aug 2026: Microsoft Teams for Android Spoofing Vulnerability Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Teams
CVE-2026-62898 Aug 11, 2026
Aug 2026: Microsoft QUIC Information Disclosure Vulnerability Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Net
Visual Studio 2022
Visual Studio 2026
And others...
CVE-2026-62738 Aug 11, 2026
Aug 2026: Windows Management Instrumentation Information Disclosure Vulnerability Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Windows 10
Windows Server 2019
Windows Server 2022
And others...
CVE-2026-71331 Aug 11, 2026
Aug 2026: Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
Windows 10
Windows Server 2019
Windows Server 2022
And others...
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.