Power Automate For Desktop Microsoft Power Automate For Desktop

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Power Automate For Desktop.

By the Year

In 2026 there have been 2 vulnerabilities in Microsoft Power Automate For Desktop with an average score of 6.8 out of ten. Last year, in 2025 Power Automate For Desktop had 3 security vulnerabilities published. Right now, Power Automate For Desktop is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 1.02

Year Vulnerabilities Average Score
2026 2 6.75
2025 3 7.77
2024 1 8.50

It may take a day or so for new Power Automate For Desktop vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Power Automate For Desktop Security Vulnerabilities

Sep 2026: Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
CVE-2026-77897 7 - High - September 08, 2026

Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.

Relative Path Traversal

May 2026: Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2026-40374 6.5 - Medium - May 12, 2026

Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.

Information Disclosure

Jun 2025: Power Automate Elevation of Privilege Vulnerability
CVE-2025-47966 9.8 - Critical - June 05, 2025

Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.

Information Disclosure

Apr 2025: Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2025-29817 5.7 - Medium - April 15, 2025

Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

DLL preloading

Jan 2025: Microsoft Power Automate Remote Code Execution Vulnerability
CVE-2025-21187 7.8 - High - January 14, 2025

Microsoft Power Automate Remote Code Execution Vulnerability

Code Injection

Sep 2024: Microsoft Power Automate Desktop Remote Code Execution Vulnerability
CVE-2024-43479 8.5 - High - September 10, 2024

Microsoft Power Automate Desktop Remote Code Execution Vulnerability

Authorization

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Power Automate For Desktop or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe