Security
CVE detail from Microsoft's public MSRC CVRF API, cross-checked with CISA's Known Exploited Vulnerabilities catalog. Counts cover Microsoft-issued CVEs; republished third-party CVEs such as Chromium or Linux are hidden unless you include them.
| CVE | Vulnerability | Severity | CVSS | EPSS | Impact | Status | Fixed by |
|---|---|---|---|---|---|---|---|
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege VulnerabilityMicrosoft Azure Active Directory B2C | Critical | 10.0 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-83944 | Azure Logic Apps Elevation of Privilege VulnerabilityAzure Logic Apps | Critical | 10.0 | 0.4% | Elevation of Privilege | Service-side fix | |
| CVE-2026-85889 | Azure AI Foundry Elevation of Privilege VulnerabilityAzure AI Foundry | Critical | 10.0 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-45499 | Azure OpenAI Elevation of Privilege VulnerabilityAzure OpenAI | Critical | 9.9 | 0.8% | Elevation of Privilege | Revised 9 Sep | Service-side fix |
| CVE-2026-50481 | Azure Active Directory Elevation of Privilege VulnerabilityAzure Active Directory | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-50515 | Azure Service Bus Remote Code Execution VulnerabilityAzure Service Bus | Critical | 9.9 | 1.7% | Remote Code Execution | Service-side fix | |
| CVE-2026-50517 | Microsoft M365 Copilot Remote Code Execution VulnerabilityM365 Copilot | Critical | 9.9 | 1.7% | Remote Code Execution | Service-side fix | |
| CVE-2026-54120 | Microsoft Surface Remote Code Execution VulnerabilityMicrosoft Surface | Critical | 9.9 | 1.0% | Remote Code Execution | Service-side fix | |
| CVE-2026-57100 | Microsoft Entra Provisioning Service Elevation of Privilege VulnerabilityMicrosoft Entra Provisioning Service (SyncFabric) | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-59115 | Microsoft Entra Provisioning Service Elevation of Privilege VulnerabilityMicrosoft Entra Provisioning Service (SyncFabric) | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62830 | Azure SRE Agent Elevation of Privilege VulnerabilityAzure SRE Agent | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-63509 | Microsoft Fabric Elevation of Privilege VulnerabilityMicrosoft Fabric | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-68782 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-68789 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 9.9 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69851 | Microsoft Entra ID Elevation of Privilege VulnerabilityAzure Active Directory | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-83941 | Entra ID Elevation of Privilege VulnerabilityEntra ID | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-85878 | Azure Database for PostgreSQL Elevation of Privilege VulnerabilityAzure Database for PostgreSQL | Critical | 9.9 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-85885 | Microsoft 365 Copilot Elevation of Privilege VulnerabilityM365 Copilot | Critical | 9.9 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-55010 | Minecraft Bedrock Dedicated Server Remote Code Execution VulnerabilityMinecraft Bedrock Dedicated Server | Critical | 9.8 | 1.0% | Remote Code Execution | Service-side fix | |
| CVE-2026-56165 | Microsoft Account Remote Code Execution VulnerabilityMicrosoft Account | Critical | 9.8 | 1.0% | Remote Code Execution | Service-side fix | |
| CVE-2026-62873 | Microsoft 365 Admin Center Elevation of Privilege VulnerabilityMicrosoft 365 Admin Center | Critical | 9.8 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-56161 | Azure Logic Apps Information Disclosure VulnerabilityAzure Logic Apps | Critical | 9.6 | 0.7% | Information Disclosure | Service-side fix | |
| CVE-2026-62896 | Microsoft Teams Elevation of Privilege VulnerabilityMicrosoft Teams | Critical | 9.6 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69400 | Azure Logic Apps Elevation of Privilege VulnerabilityAzure Logic Apps | Critical | 9.6 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-70332 | Microsoft Office SharePoint Spoofing VulnerabilityMicrosoft Office SharePoint | Critical | 9.6 | 0.9% | Spoofing | Service-side fix | |
| CVE-2026-87701 | Azure Cosmos DB Elevation of Privilege VulnerabilityAzure Cosmos DB | Critical | 9.6 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-50516 | Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityMicrosoft Azure Kubernetes Service | Critical | 9.4 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-41106 | Microsoft 365 Copilot Elevation of Privilege VulnerabilityM365 Copilot | Critical | 9.3 | 0.7% | Elevation of Privilege | Service-side fix | |
| CVE-2026-59118 | Copilot Cowork Elevation of Privilege VulnerabilityCopilot Cowork | Critical | 9.3 | 0.7% | Elevation of Privilege | Revised 11 Aug | Service-side fix |
| CVE-2026-62834 | Azure Data Factory Elevation of Privilege VulnerabilityAzure Data Factory | Critical | 9.3 | 0.5% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62835 | Azure Portal Information Disclosure VulnerabilityAzure Portal | Critical | 9.3 | 1.0% | Information Disclosure | Revised 24 Jul | Service-side fix |
| CVE-2026-70009 | Azure Arc Elevation of Privilege VulnerabilityAzure Arc | Critical | 9.3 | 0.5% | Elevation of Privilege | Service-side fix | |
| CVE-2026-80098 | Copilot Studio Elevation of Privilege VulnerabilityCopilot Studio | Critical | 9.3 | 0.5% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62916 | Microsoft Entra ID Elevation of Privilege VulnerabilityMicrosoft Entra ID | Critical | 9.1 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-66309 | Azure SQL Database Elevation of Privilege VulnerabilityAzure SQL Database | Critical | 9.1 | 0.9% | Elevation of Privilege | Service-side fix | |
| CVE-2026-68823 | Azure Confidential Ledger Remote Code Execution VulnerabilityAzure Confidential Ledger | Critical | 9.1 | 0.9% | Remote Code Execution | Service-side fix | |
| CVE-2026-77903 | Microsoft Dataverse Elevation of Privilege VulnerabilityMicrosoft Dataverse | Critical | 9.0 | 0.4% | Elevation of Privilege | Service-side fix | |
| CVE-2026-24301 | Microsoft Copilot Information Disclosure VulnerabilityMicrosoft Copilot | Critical | 8.8 | 4.1% | Information Disclosure | Revised 25 Aug | Service-side fix |
| CVE-2026-49163 | Application Insights Profiler Elevation of Privilege VulnerabilityApplication Insights Profiler | Critical | 8.8 | 1.0% | Elevation of Privilege | Service-side fix | |
| CVE-2026-54998 | Microsoft Exchange Online Elevation of Privilege VulnerabilityMicrosoft Exchange Online | Critical | 8.8 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62869 | Azure Entra ID Spoofing VulnerabilityAzure Entra ID | Critical | 8.8 | 0.4% | Spoofing | Service-side fix | |
| CVE-2026-65668 | Microsoft Purview eDiscovery Elevation of Privilege VulnerabilityMicrosoft Purview eDiscovery | Critical | 8.8 | 0.8% | Elevation of Privilege | Service-side fix | |
| CVE-2026-62836 | Azure SQL Managed Instance Elevation of Privilege VulnerabilityAzure SQL Managed Instance | Critical | 8.7 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-66800 | Azure Data Factory Information Disclosure VulnerabilityAzure Data Factory | Critical | 8.6 | 1.0% | Information Disclosure | Service-side fix | |
| CVE-2026-68791 | Azure Machine Learning Information Disclosure VulnerabilityAzure Machine Learning | Critical | 8.6 | 0.5% | Information Disclosure | Service-side fix | |
| CVE-2026-69519 | Azure Stack HCI Information Disclosure VulnerabilityAzure Stack HCI | Critical | 8.6 | 1.0% | Information Disclosure | Service-side fix | |
| CVE-2026-69558 | Microsoft Partner Center Information Disclosure VulnerabilityMicrosoft Partner Center | Critical | 8.6 | 1.0% | Information Disclosure | Service-side fix | |
| CVE-2026-56167 | Azure AI Search Elevation of Privilege VulnerabilityAzure AI Search | Critical | 8.5 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-65818 | Power Automate Elevation of Privilege VulnerabilityPower Automate | Critical | 8.5 | 0.6% | Elevation of Privilege | Service-side fix | |
| CVE-2026-69419 | Azure Data Manager for Energy Remote Code Execution VulnerabilityAzure Data Manager for Energy | Critical | 8.5 | 0.7% | Remote Code Execution | Service-side fix |
CISA KEV · Microsoft additions
389 Microsoft CVEs listedCVE-2026-65660
SharePoint
Microsoft SharePoint Code Injection VulnerabilityCVE-2026-85880
Windows
Microsoft Windows Heap-Based Buffer Overflow VulnerabilityCVE-2026-81963
Windows
Microsoft Windows Link Following VulnerabilityCVE-2019-1068
SQL Server
Microsoft SQL Server Remote Code Execution VulnerabilityCVE-2026-55040
SharePoint
Microsoft SharePoint Weak Authentication VulnerabilityCVE-2026-33824
Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityCVE-2026-68820
Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free VulnerabilityCVE-2026-50522
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-58644
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityCVE-2026-56164
SharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function VulnerabilityCVE-2026-56155
Active Directory Federation Services
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Security news
AllFri 25 Sep1 item
Thu 24 Sep2 items
Wed 23 Sep3 items
Tue 22 Sep1 item
Thu 17 Sep2 items
Tue 15 Sep1 item
Mon 14 Sep1 item
Thu 10 Sep1 item