Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2026-26138
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview
Mitigation only
CRITICAL 9.9
CVE-2026-26137
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
365 Copilot Chat
No fix yet
HIGH 8.6
CVE-2026-26139
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview
No fix yet
HIGH 7.5
CVE-2026-26136
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …
Copilot
Mitigation only
HIGH 7.5
CVE-2026-26120
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.
Bing
No fix yet
MEDIUM 5.3
CVE-2026-24299
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot
Mitigation only
HIGH 7.5
CVE-2026-23659
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo…
Azure Data Factory
No fix yet
CRITICAL 9.8
CVE-2026-23658
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
No fix yet
HIGH 8.8
CVE-2026-26114
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
Mitigation only
HIGH 8.8
CVE-2026-20967
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
System Center Operations Manager
Mitigation only
CRITICAL 9.8
CVE-2026-26125
Payment Orchestrator Service Elevation of Privilege Vulnerability
Payment Orchestrator Service
No fix yet
MEDIUM 6.7
CVE-2026-23651
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
Aci Confidential Containers
Mitigation only
MEDIUM 6.7
CVE-2026-26124
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
Aci Confidential Containers
No fix yet
MEDIUM 6.5
CVE-2026-26122
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
Aci Confidential Containers
No fix yet
CRITICAL 9.8
CVE-2026-21536
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Devices Pricing Program
No fix yet
HIGH 7.5
CVE-2026-21535
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
Teams
Mitigation only
CRITICAL 9.8
CVE-2026-21531
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
Azure Conversation Authoring Client Library
Mitigation only
HIGH 8.8
CVE-2026-21537
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj…
Defender For Endpoint
Mitigation only
HIGH 7.8
CVE-2026-21514 KEV
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
365 Apps
Mitigation only
CRITICAL 9.8
CVE-2026-24300
Azure Front Door Elevation of Privilege Vulnerability
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-24302
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Arc
Mitigation only
HIGH 8.2
CVE-2026-21532
Azure Function Information Disclosure Vulnerability
Azure Functions
No fix yet
HIGH 7.8
CVE-2026-21509 KEVEPSS 72%
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
365 Apps
Mitigation only
CRITICAL 9.9
CVE-2026-24304
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Azure Resource Manager
Mitigation only
HIGH 7.5
CVE-2026-24307
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-24305
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2026-24306
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-21227
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…
Azure Logic Apps
Mitigation only
HIGH 7.5
CVE-2026-21520
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …
Copilot Studio
Mitigation only
HIGH 7.4
CVE-2026-21521
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
365 Word Copilot
Mitigation only