Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.3
CVE-2026-59118
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Power Apps
No fix yet
HIGH 7.5
CVE-2026-62835
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Azure Portal
No fix yet
CRITICAL 9.9
CVE-2026-56160
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Azure Red Hat Openshift
No fix yet
HIGH 7.8
CVE-2026-58540
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-58277
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
Mitigation only
HIGH 8.8
CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-50344
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-50346
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-58631
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Windows Admin Center
2606+
HIGH 7.8
CVE-2026-49170
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 8.3
CVE-2026-58284
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
CRITICAL 10.0
CVE-2026-57983
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Edge Chromium
150.0.4078.48+
HIGH 8.0
CVE-2026-47298
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20384+
MEDIUM 6.5
CVE-2026-45503
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Exchange Server
15.02.2562.043+
HIGH 7.8
CVE-2026-45490
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
.net
8.0.28 / 9.0.17+
HIGH 7.8
CVE-2026-42902
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
Powertoys
0.99.1+
HIGH 7.5
CVE-2026-48579
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
Exchange Online
Mitigation only
MEDIUM 6.5
CVE-2026-33823
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
Teams
No fix yet
HIGH 8.0
CVE-2026-27912
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
Windows Server 2012
10.0.14393.9060 / 10.0.17763.8644+
CRITICAL 9.8
CVE-2026-33105
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
Mitigation only
CRITICAL 9.8
CVE-2026-32213
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.8
CVE-2026-24305
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
HIGH 8.0
CVE-2026-20960
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Power Apps
3.25121+
CRITICAL 9.8
CVE-2025-65041
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Partner Center
Mitigation only
CRITICAL 9.8
CVE-2025-64655
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
Dynamics Omnichannel Sdk Storage Containers
No fix yet
HIGH 8.7
CVE-2025-59271
Redis Enterprise Elevation of Privilege Vulnerability
Azure Cache For Redis
No fix yet
CRITICAL 9.8
CVE-2025-53795
Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
Pc Manager
Mitigation only
CRITICAL 9.1
CVE-2025-53792
Azure Portal Elevation of Privilege Vulnerability
Azure Portal
No fix yet
HIGH 8.8
CVE-2025-49746
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
Mitigation only
HIGH 8.8
CVE-2025-49701
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.18526.20424+