Microsoft Power Automate For Desktop
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Power Automate For Desktop.
By the Year
In 2026 there have been 2 vulnerabilities in Microsoft Power Automate For Desktop with an average score of 6.8 out of ten. Last year, in 2025 Power Automate For Desktop had 3 security vulnerabilities published. Right now, Power Automate For Desktop is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 1.02
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 6.75 |
| 2025 | 3 | 7.77 |
| 2024 | 1 | 8.50 |
It may take a day or so for new Power Automate For Desktop vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Power Automate For Desktop Security Vulnerabilities
Sep 2026: Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
CVE-2026-77897
7 - High
- September 08, 2026
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
Relative Path Traversal
May 2026: Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2026-40374
6.5 - Medium
- May 12, 2026
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
Information Disclosure
Jun 2025: Power Automate Elevation of Privilege Vulnerability
CVE-2025-47966
9.8 - Critical
- June 05, 2025
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
Information Disclosure
Apr 2025: Microsoft Power Automate Desktop Information Disclosure Vulnerability
CVE-2025-29817
5.7 - Medium
- April 15, 2025
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
DLL preloading
Jan 2025: Microsoft Power Automate Remote Code Execution Vulnerability
CVE-2025-21187
7.8 - High
- January 14, 2025
Microsoft Power Automate Remote Code Execution Vulnerability
Code Injection
Sep 2024: Microsoft Power Automate Desktop Remote Code Execution Vulnerability
CVE-2024-43479
8.5 - High
- September 10, 2024
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
Authorization
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Power Automate For Desktop or by Microsoft? Click the Watch button to subscribe.