Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.6 CRITICAL
CVE-2026-87701 — Azure Cosmos DB Elevation of Privilege Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-85917 — Azure AI Foundry Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-85889 — Azure AI Foundry Elevation of Privilege Vulnerability

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.9 CRITICAL
CVE-2026-85885 — Microsoft 365 Copilot Elevation of Privilege Vulnerability

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-83944 — Azure Logic Apps Elevation of Privilege Vulnerability

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-78501 — Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.0 CRITICAL
CVE-2026-77903 — Microsoft Dataverse Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-70200 — Azure Logic Apps Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.3 CRITICAL
CVE-2026-70009 — Azure Arc Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-69865 — Microsoft Container Registry Elevation of Privilege Vulnerability

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-69399 — Azure Arc Elevation of Privilege Vulnerability

Azure Arc Elevation of Privilege Vulnerability

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.6 HIGH
CVE-2026-68791 — Azure Machine Learning Information Disclosure Vulnerability

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.1 MEDIUM
CVE-2026-55946 — Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.5 HIGH
CVE-2026-93426 — SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or highe…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-93307 — O-RAN-SC SMO OAM VES Collector memory allocation

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to unco…

smo_oam | Remote | Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-86688 — Session id is not renewed on authentication in ash_authentication, allowing session fixat…

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs i…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.1 CRITICAL
CVE-2026-76949 — Remember-me sign-in guard reads a session key that is never written in ash_authentication…

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated s…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-73639 — Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row…

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds …

imager | Memory Corruption
Sep 17, 2026 Sep 18, 2026
Sep 17, 2026
Sep 18, 2026
0.0 NA
CVE-2026-73638 — Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchec…

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->of…

imager | Memory Corruption
Sep 17, 2026 Sep 18, 2026
Sep 17, 2026
Sep 18, 2026
9.1 CRITICAL
CVE-2026-54767 — WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only …

wegia | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14441 Results