Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-62827
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20522+
CRITICAL 9.6
CVE-2026-62896
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Teams
No fix yet
CRITICAL 10.0
CVE-2026-56162
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Azure Sql Database
No fix yet
CRITICAL 9.8
CVE-2026-62825
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Azure Key Vault
No fix yet
CRITICAL 10.0
CVE-2026-56191
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Exchange Online
No fix yet
HIGH 8.0
CVE-2026-50365
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.8
CVE-2026-56169
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2606+
HIGH 7.8
CVE-2026-57107
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Windows Admin Center
2606+
MEDIUM 6.5
CVE-2026-56185
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Windows Admin Center
2511+
HIGH 8.2
CVE-2026-50338
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Azure Spring Cloud
7.3.0+
CRITICAL 10.0
CVE-2026-45480
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Azure Active Directory
No fix yet
HIGH 8.8
CVE-2026-32174
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
HIGH 7.8
CVE-2026-44810
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
Windows 11 23h2
10.0.20348.5256 / 10.0.22631.7219+
CRITICAL 9.8
CVE-2026-47280
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
Azure Resource Manager
No fix yet
CRITICAL 10.0
CVE-2026-42822
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
Azure Local
2604.2.25645+
CRITICAL 9.1
CVE-2026-33117
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…
Azure Sdk For Java
4.10.6+
MEDIUM 6.2
CVE-2026-32072
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
HIGH 7.5
CVE-2026-32173
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
Azure Sre Agent
Mitigation only
HIGH 7.8
CVE-2026-26141
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Azure Automation Hybrid Worker Windows Extension
1.3.74+
HIGH 7.8
CVE-2026-26128
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 7.8
CVE-2026-24294
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8957 / 10.0.17763.8511+
HIGH 8.8
CVE-2026-26119
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2511+
HIGH 7.0
CVE-2026-21508
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.0
CVE-2025-55340
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.
Windows 10 21h2
10.0.19044.6456 / 10.0.19045.6456+
CRITICAL 9.8
CVE-2025-55234EPSS 20%
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p…
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
HIGH 8.8
CVE-2025-54918EPSS 19%
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
CRITICAL 10.0
CVE-2025-55241
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
HIGH 7.5
CVE-2025-53793
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
Azure Stack Hub
1.2406.1.23 / 1.2408.1.50+
HIGH 8.8
CVE-2025-53778EPSS 38%
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.21100 / 10.0.14393.8330+
HIGH 8.0
CVE-2025-53786EPSS 7%
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made…
Exchange Server
15.02.2562.017+