Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-47290
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.5
CVE-2026-50652
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
.net Framework
Mitigation only
HIGH 7.5
CVE-2026-50653
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
.net Framework
No fix yet
HIGH 7.8
CVE-2026-48581
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Surface Go 2 1901 Firmware
No fix yet
CRITICAL 9.6
CVE-2026-48561
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
365 Copilot
Mitigation only
HIGH 8.8
CVE-2026-47632
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
Azure Connected Machine Agent
Mitigation only
MEDIUM 6.1
CVE-2026-47646
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t…
Dynamics 365 Customer Voice
Mitigation only
HIGH 8.8
CVE-2026-45499
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Azure Openai
Mitigation only
HIGH 8.8
CVE-2026-54998
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Exchange Online
No fix yet
HIGH 8.8
CVE-2026-57100
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…
Entra Provisioning Service
Mitigation only
CRITICAL 9.3
CVE-2026-41106
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-26145
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Azure Synapse
No fix yet
HIGH 7.5
CVE-2025-66389
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpa…
Github Copilot
No fix yet
HIGH 8.8
CVE-2026-48584
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Azure Synapse
No fix yet
CRITICAL 9.6
CVE-2026-48582
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Exchange Online
Mitigation only
HIGH 8.8
CVE-2026-47645
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov…
365 Copilot
Mitigation only
CRITICAL 10.0
CVE-2026-45480
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Azure Active Directory
No fix yet
HIGH 7.5
CVE-2026-42895
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…
365 Copilot
Mitigation only
MEDIUM 5.4
CVE-2026-32208
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s…
Edge Chromium
Mitigation only
CRITICAL 9.1
CVE-2025-62821
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the report…
Heif Image Extension
No fix yet
HIGH 7.5
CVE-2026-54130
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
Mitigation only
CRITICAL 9.9
CVE-2026-47647
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
Dynamics 365
Mitigation only
HIGH 7.5
CVE-2026-47633
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose inf…
Cost Management
No fix yet
HIGH 8.8
CVE-2026-32174
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
HIGH 7.0
CVE-2026-50656EPSS 11%
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP…
Malware Protection Engine
No fix yet
HIGH 7.8
CVE-2026-48565
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Windows Narrator Braille
Mitigation only
HIGH 8.4
CVE-2026-47635
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Office 2024
Mitigation only
HIGH 7.0
CVE-2026-47293
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 7.1
CVE-2026-45649
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Excel
No fix yet
HIGH 7.8
CVE-2026-45645
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only