Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.6 CRITICAL
CVE-2026-70332 — Microsoft Office SharePoint Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.1 CRITICAL
CVE-2026-68823 — Azure Confidential Ledger Remote Code Execution Vulnerability

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.8 HIGH
CVE-2026-65668 — Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
10.0 CRITICAL
CVE-2026-65667 — Microsoft Teams Elevation of Privilege Vulnerability

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
10.0 CRITICAL
CVE-2026-63508 — Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-62918 — Microsoft Teams Spoofing Vulnerability

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-62896 — Microsoft Teams Elevation of Privilege Vulnerability

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.8 CRITICAL
CVE-2026-62873 — Microsoft 365 Admin Center Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-62836 — Azure SQL Managed Instance Elevation of Privilege Vulnerability

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-62830 — Azure SRE Agent Elevation of Privilege Vulnerability

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.3 CRITICAL
CVE-2026-59118 — Microsoft Power Apps Elevation of Privilege Vulnerability

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-59115 — Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
10.0 CRITICAL
CVE-2026-56162 — Azure SQL Database Elevation of Privilege Vulnerability

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-56161 — Azure Logic Apps Information Disclosure Vulnerability

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-50515 — Azure Service Bus Remote Code Execution Vulnerability

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-50481 — Azure Active Directory Elevation of Privilege Vulnerability

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.8 HIGH
CVE-2026-49163 — Application Insights Profiler Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.3 MEDIUM
CVE-2026-17264 — Medixant RadiAnt DICOM Out-of-bounds write

Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

Remote | Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.8 HIGH
CVE-2026-8325 — PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corr…

revit | Memory Corruption
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.8 HIGH
CVE-2026-7867 — Udisks2: udisks2: local privilege escalation via as-user option spoofing

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() …

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 10128 Results