LIVE · cybersecurity feed
Live wire
vendor4 exploited in the wild

Microsoft

300 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical109
High191
Medium0
Exploited (KEV)4

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-50522exploited9.8criticalsharepoint serverDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o53d ago
CVE-2026-58644exploited9.8criticalsharepoint serverDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o53d ago
CVE-2026-55040exploited9.1criticalsharepoint serverWeak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature ov53d ago
CVE-2026-45659exploited8.8highsharepoint serverDeserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove106d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-6950210criticalazure sql databaseServer-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges ove15d ago
CVE-2026-6350810criticalplanetary computerMissing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker t30d ago
CVE-2026-5863010criticalazure app service for linuxImproper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.43d ago
CVE-2026-6566710criticalteamsMissing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.30d ago
CVE-2026-6580110criticalexchange onlineServer-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privile16d ago
CVE-2026-6282510criticalazure key vaultImproper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.44d ago
CVE-2026-6680310criticalazure cosmos dbImproper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.37d ago
CVE-2026-4041210criticalazure orbital spatioUnrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute106d ago
CVE-2026-6983610criticalentra idDeserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a net16d ago
CVE-2026-4548010criticalazure active directoryImproper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a net78d ago
CVE-2026-4110410criticalplanetary computerDeserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose 106d ago
CVE-2026-6577010criticalazure managed instance for apache cassandraImproper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for A16d ago
CVE-2026-6581610criticalazure web appsUse of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges o16d ago
CVE-2026-5827510criticalazure dnsMissing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.44d ago
CVE-2026-3216910criticalazure cloud shellServer-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over170d ago
CVE-2026-4282210criticalazure localImproper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileg110d ago
CVE-2026-5710610criticalpurview data governanceServer-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a ne43d ago
CVE-2026-4856710criticalazure horizondbAuthentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a 93d ago
CVE-2026-5616210criticalazure sql databaseImproper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network30d ago
CVE-2026-5616310criticalazure kubernetes serviceMissing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker43d ago
CVE-2026-4290110criticalentra idOrigin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network106d ago
CVE-2026-2365210criticalpower pagesImproper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allow106d ago
CVE-2026-5619110criticalexchange onlineImproper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a n44d ago
CVE-2026-6955510criticalazure arcIncorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.16d ago
CVE-2026-4728010criticalazure resource managerImproper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over106d ago
CVE-2026-505179.9critical365 copilotDeserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.44d ago
CVE-2026-628309.9criticalazure sre agentMissing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.30d ago
CVE-2026-687899.9criticalazure sql databaseImproper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows 16d ago
CVE-2026-591159.9criticalentra provisioning service'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileg30d ago
CVE-2026-504819.9criticalazure active directoryModification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate p30d ago
CVE-2026-570929.9criticalwindows 10 1607Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.53d ago
CVE-2026-261379.9critical365 copilot chatServer-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over 170d ago
CVE-2026-428239.9criticalazure logic appsImproper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.116d ago
CVE-2026-404119.9criticalazure virtual network gatewayImproper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a ne106d ago
CVE-2026-698519.9criticalentra idServer-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges o16d ago
CVE-2026-505159.9criticalazure service busDeserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a networ30d ago
CVE-2026-476479.9criticaldynamics 365Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a netwo79d ago
CVE-2026-635099.9criticalfabricRelative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.16d ago
CVE-2026-485849.9criticalazure synapseExecution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a 78d ago
CVE-2026-428989.9criticaldynamics 365Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an author116d ago
CVE-2026-541209.9criticalsurface management servicesImproper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.44d ago
CVE-2026-687829.9criticalazure sql databaseImproper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows 16d ago
CVE-2026-571009.9criticalentra provisioning serviceServer-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attac65d ago
CVE-2026-454999.9criticalazure openaiServer-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a netw65d ago
CVE-2026-628739.8criticalwindows admin centerImproper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to 30d ago
CVE-2026-628789.8criticalwindows 10 1607Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.25d ago
CVE-2026-505189.8criticalwindows 10 1607Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.53d ago
CVE-2026-591249.8criticalwindows appDeserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attack25d ago
CVE-2026-410969.8criticalwindows 11 23h2Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network116d ago
CVE-2026-561599.8criticalwindows 10 1607Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.53d ago
CVE-2026-491729.8criticalwindows 10 1607Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.53d ago
CVE-2026-628159.8criticalwindows 11 23h2Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.25d ago
CVE-2026-541189.8criticalsql server 2016Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.53d ago
CVE-2026-541309.8critical365 copilotMissing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose informati79d ago
CVE-2026-549909.8criticalwindows 11 24h2Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network53d ago
CVE-2026-456579.8criticalwindows 11 23h2Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.88d ago
CVE-2026-541179.8criticalsql server 2016Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.53d ago
CVE-2026-472919.8criticalwindows 10 1607Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.88d ago
CVE-2026-50522exploited9.8criticalsharepoint serverDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o53d ago
CVE-2026-476439.8criticalazure stack edgeExternal control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a n88d ago
CVE-2026-429909.8criticalwindows 10 1607Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a networ53d ago
CVE-2026-504479.8criticalwindows 10 1607Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a netwo53d ago
CVE-2026-261429.8criticalnuance powerscribe 360Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a net88d ago
CVE-2026-550109.8criticalminecraft bedrock dedicated serverHeap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code o53d ago
CVE-2026-559449.8criticaldynamics navDeserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a53d ago
CVE-2026-561889.8criticalwindows 10 1607Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Netw53d ago
CVE-2026-628939.8criticalwindows 10 1607Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.25d ago
CVE-2026-321919.8criticalbing imagesImproper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Image170d ago
CVE-2026-321949.8criticalbing imagesImproper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allow170d ago
CVE-2026-58644exploited9.8criticalsharepoint serverDeserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o53d ago
CVE-2026-410899.8criticalwindows server 2012Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.116d ago
CVE-2026-448159.8criticalwindows 10 1607Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.88d ago
CVE-2026-561909.8criticalwindows 10 1607Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.53d ago
CVE-2026-657919.8criticalwindows 10 1607Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a 25d ago
CVE-2026-561659.8criticalaccountHeap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.44d ago
CVE-2026-703329.6criticalsharepoint onlineImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin30d ago
CVE-2026-472819.6criticalvisual studio codeMissing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.88d ago
CVE-2026-628969.6criticalteamsImproper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.30d ago
CVE-2026-561619.6criticalazure logic appsImproper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.30d ago
CVE-2026-429049.6criticalwindows 10 21h2Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacen88d ago
CVE-2026-550089.6criticalexchange serverImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server 53d ago
CVE-2026-416159.6criticalauthenticatorExposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attac114d ago
CVE-2026-485619.6critical365 copilotImproper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edg53d ago
CVE-2026-694009.6criticalazure logic appsImproper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unaut16d ago
CVE-2026-503809.6criticalwindows 10 1607Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.53d ago
CVE-2026-485829.6criticalexchange onlineMissing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a netw78d ago
CVE-2026-505169.4criticalazure kubernetes serviceMissing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker25d ago
CVE-2026-628359.3criticalazure portalImproper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.43d ago
CVE-2026-591189.3criticalpower appsImproper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.30d ago
CVE-2026-497989.3criticalwindows 10 1607Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.53d ago
CVE-2026-410909.3critical365 copilotImproper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an106d ago
CVE-2026-404029.3criticalwindows 11 23h2Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.116d ago
CVE-2026-411069.3critical365 copilotUrl redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate pri65d ago
CVE-2026-703069.3criticalsharepoint serverImproper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin25d ago
CVE-2026-403799.3criticalentra idExposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to pe116d ago
CVE-2026-476469.3criticaldynamics 365 customer voiceImproper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voic59d ago
CVE-2026-628349.3criticalazure data factoryImproper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate 16d ago
CVE-2026-688239.1criticalazure confidential ledgerExposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code ov30d ago
CVE-2026-411039.1criticalconfluence saml ssoIncorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an u116d ago
CVE-2026-428339.1criticaldynamics 365Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an author116d ago

Filter the full tracker by Microsoft

Our coverage of Microsoft

microsoft

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Several cybersecurity-related developments have occurred, including Microsoft releasing patches for its cloud services. Additionally, hackers gained access to approximately 5,000 Dropbox accounts. In business news, cybersecurity startup Guardio has achieved a valuation of $1.1 billion.

phishinghigh

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft has identified a large-scale phishing campaign that utilizes invisible Unicode tag characters to bypass email filters. Attackers embed these characters within financial keywords, splitting them to evade detection while appearing normal to recipients. This technique, dubbed ASCII smuggling, was used in millions of emails over several months, often masquerading as business loan or funding opportunities.

security

Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

A shared security 'Nightmare'

security

Microsoft Teams Has Become a Haven for Scammers in China

Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.

patch

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]

CVE-2026-63520critical

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Rapid7 has published a technical analysis of CVE-2026-63520, a critical remote code execution vulnerability in Microsoft SharePoint. The vulnerability allows an authenticated attacker to execute arbitrary code on a vulnerable server by uploading a malicious BDC model file. When combined with another vulnerability, CVE-2026-55040, it can lead to unauthenticated RCE.

scamhigh

Fake Microsoft security scans trick victims into uninstalling their antivirus

Scammers are operating fake Microsoft-branded websites that mimic security scans to trick users into uninstalling their antivirus software. These sites present fabricated security issues, falsely claim third-party antivirus is unsupported, and then guide victims toward a refund scam. The ultimate goal is to obtain personal information, banking details, and remote access to the victim's computer.

security

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]

patch

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]

patch

Microsoft shares temporary fix for Windows 11 gaming issues

Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]

phishing

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]

vulnerability

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine. The driver, BTR.sys (Boot Time Removal Tool), is a