| CVE-2026-69502 | 10 | critical | azure sql database | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges ove | 15d ago |
| CVE-2026-63508 | 10 | critical | planetary computer | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker t | 30d ago |
| CVE-2026-58630 | 10 | critical | azure app service for linux | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | 43d ago |
| CVE-2026-65667 | 10 | critical | teams | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-65801 | 10 | critical | exchange online | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privile | 16d ago |
| CVE-2026-62825 | 10 | critical | azure key vault | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 44d ago |
| CVE-2026-66803 | 10 | critical | azure cosmos db | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | 37d ago |
| CVE-2026-40412 | 10 | critical | azure orbital spatio | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute | 106d ago |
| CVE-2026-69836 | 10 | critical | entra id | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a net | 16d ago |
| CVE-2026-45480 | 10 | critical | azure active directory | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a net | 78d ago |
| CVE-2026-41104 | 10 | critical | planetary computer | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose | 106d ago |
| CVE-2026-65770 | 10 | critical | azure managed instance for apache cassandra | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for A | 16d ago |
| CVE-2026-65816 | 10 | critical | azure web apps | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges o | 16d ago |
| CVE-2026-58275 | 10 | critical | azure dns | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 44d ago |
| CVE-2026-32169 | 10 | critical | azure cloud shell | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over | 170d ago |
| CVE-2026-42822 | 10 | critical | azure local | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileg | 110d ago |
| CVE-2026-57106 | 10 | critical | purview data governance | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a ne | 43d ago |
| CVE-2026-48567 | 10 | critical | azure horizondb | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a | 93d ago |
| CVE-2026-56162 | 10 | critical | azure sql database | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network | 30d ago |
| CVE-2026-56163 | 10 | critical | azure kubernetes service | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker | 43d ago |
| CVE-2026-42901 | 10 | critical | entra id | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network | 106d ago |
| CVE-2026-23652 | 10 | critical | power pages | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allow | 106d ago |
| CVE-2026-56191 | 10 | critical | exchange online | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a n | 44d ago |
| CVE-2026-69555 | 10 | critical | azure arc | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 16d ago |
| CVE-2026-47280 | 10 | critical | azure resource manager | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over | 106d ago |
| CVE-2026-50517 | 9.9 | critical | 365 copilot | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | 44d ago |
| CVE-2026-62830 | 9.9 | critical | azure sre agent | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-68789 | 9.9 | critical | azure sql database | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows | 16d ago |
| CVE-2026-59115 | 9.9 | critical | entra provisioning service | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileg | 30d ago |
| CVE-2026-50481 | 9.9 | critical | azure active directory | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate p | 30d ago |
| CVE-2026-57092 | 9.9 | critical | windows 10 1607 | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | 53d ago |
| CVE-2026-26137 | 9.9 | critical | 365 copilot chat | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over | 170d ago |
| CVE-2026-42823 | 9.9 | critical | azure logic apps | Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | 116d ago |
| CVE-2026-40411 | 9.9 | critical | azure virtual network gateway | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a ne | 106d ago |
| CVE-2026-69851 | 9.9 | critical | entra id | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges o | 16d ago |
| CVE-2026-50515 | 9.9 | critical | azure service bus | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a networ | 30d ago |
| CVE-2026-47647 | 9.9 | critical | dynamics 365 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a netwo | 79d ago |
| CVE-2026-63509 | 9.9 | critical | fabric | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | 16d ago |
| CVE-2026-48584 | 9.9 | critical | azure synapse | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a | 78d ago |
| CVE-2026-42898 | 9.9 | critical | dynamics 365 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an author | 116d ago |
| CVE-2026-54120 | 9.9 | critical | surface management services | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | 44d ago |
| CVE-2026-68782 | 9.9 | critical | azure sql database | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows | 16d ago |
| CVE-2026-57100 | 9.9 | critical | entra provisioning service | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attac | 65d ago |
| CVE-2026-45499 | 9.9 | critical | azure openai | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a netw | 65d ago |
| CVE-2026-62873 | 9.8 | critical | windows admin center | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to | 30d ago |
| CVE-2026-62878 | 9.8 | critical | windows 10 1607 | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-50518 | 9.8 | critical | windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-59124 | 9.8 | critical | windows app | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attack | 25d ago |
| CVE-2026-41096 | 9.8 | critical | windows 11 23h2 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network | 116d ago |
| CVE-2026-56159 | 9.8 | critical | windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-49172 | 9.8 | critical | windows 10 1607 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-62815 | 9.8 | critical | windows 11 23h2 | Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-54118 | 9.8 | critical | sql server 2016 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-54130 | 9.8 | critical | 365 copilot | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose informati | 79d ago |
| CVE-2026-54990 | 9.8 | critical | windows 11 24h2 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 53d ago |
| CVE-2026-45657 | 9.8 | critical | windows 11 23h2 | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-54117 | 9.8 | critical | sql server 2016 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-47291 | 9.8 | critical | windows 10 1607 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-50522exploited | 9.8 | critical | sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-47643 | 9.8 | critical | azure stack edge | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a n | 88d ago |
| CVE-2026-42990 | 9.8 | critical | windows 10 1607 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a networ | 53d ago |
| CVE-2026-50447 | 9.8 | critical | windows 10 1607 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a netwo | 53d ago |
| CVE-2026-26142 | 9.8 | critical | nuance powerscribe 360 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a net | 88d ago |
| CVE-2026-55010 | 9.8 | critical | minecraft bedrock dedicated server | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-55944 | 9.8 | critical | dynamics nav | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a | 53d ago |
| CVE-2026-56188 | 9.8 | critical | windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Netw | 53d ago |
| CVE-2026-62893 | 9.8 | critical | windows 10 1607 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-32191 | 9.8 | critical | bing images | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Image | 170d ago |
| CVE-2026-32194 | 9.8 | critical | bing images | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allow | 170d ago |
| CVE-2026-58644exploited | 9.8 | critical | sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-41089 | 9.8 | critical | windows server 2012 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | 116d ago |
| CVE-2026-44815 | 9.8 | critical | windows 10 1607 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-56190 | 9.8 | critical | windows 10 1607 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-65791 | 9.8 | critical | windows 10 1607 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a | 25d ago |
| CVE-2026-56165 | 9.8 | critical | account | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | 44d ago |
| CVE-2026-70332 | 9.6 | critical | sharepoint online | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 30d ago |
| CVE-2026-47281 | 9.6 | critical | visual studio code | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 88d ago |
| CVE-2026-62896 | 9.6 | critical | teams | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-56161 | 9.6 | critical | azure logic apps | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | 30d ago |
| CVE-2026-42904 | 9.6 | critical | windows 10 21h2 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacen | 88d ago |
| CVE-2026-55008 | 9.6 | critical | exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 53d ago |
| CVE-2026-41615 | 9.6 | critical | authenticator | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attac | 114d ago |
| CVE-2026-48561 | 9.6 | critical | 365 copilot | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edg | 53d ago |
| CVE-2026-69400 | 9.6 | critical | azure logic apps | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unaut | 16d ago |
| CVE-2026-50380 | 9.6 | critical | windows 10 1607 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-48582 | 9.6 | critical | exchange online | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a netw | 78d ago |
| CVE-2026-50516 | 9.4 | critical | azure kubernetes service | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker | 25d ago |
| CVE-2026-62835 | 9.3 | critical | azure portal | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | 43d ago |
| CVE-2026-59118 | 9.3 | critical | power apps | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-49798 | 9.3 | critical | windows 10 1607 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-41090 | 9.3 | critical | 365 copilot | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an | 106d ago |
| CVE-2026-40402 | 9.3 | critical | windows 11 23h2 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-41106 | 9.3 | critical | 365 copilot | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate pri | 65d ago |
| CVE-2026-70306 | 9.3 | critical | sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 25d ago |
| CVE-2026-40379 | 9.3 | critical | entra id | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to pe | 116d ago |
| CVE-2026-47646 | 9.3 | critical | dynamics 365 customer voice | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voic | 59d ago |
| CVE-2026-62834 | 9.3 | critical | azure data factory | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate | 16d ago |
| CVE-2026-68823 | 9.1 | critical | azure confidential ledger | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code ov | 30d ago |
| CVE-2026-41103 | 9.1 | critical | confluence saml sso | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an u | 116d ago |
| CVE-2026-42833 | 9.1 | critical | dynamics 365 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an author | 116d ago |