CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability Microsoft Security 24 Juli 2026 om 16:00 Corrected the CVE description and title. This is an informational change only.
CVE-2026-62835 Azure Portal Information Disclosure Vulnerability Microsoft Security 24 Juli 2026 om 16:00 Corrected the CVE description and title. This is an informational change only.
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK Microsoft Security 24 Juli 2026 om 10:02 Information published.
CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare Microsoft Security 24 Juli 2026 om 10:02 Information published.
CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare Microsoft Security 24 Juli 2026 om 10:02 Information published.
CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62835 Online Services Information Disclosure Vulnerability Microsoft Security 23 Juli 2026 om 16:00 Improper authorization in Online Services allows an unauthorized attacker to disclose information over a network.
CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects Microsoft Security 23 Juli 2026 om 10:44 Information published.
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. Microsoft Security 23 Juli 2026 om 10:06 Information published.
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. Microsoft Security 23 Juli 2026 om 10:06 Information published.
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. Microsoft Security 23 Juli 2026 om 10:06 Information published.
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() Microsoft Security 23 Juli 2026 om 10:06 Information published.
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys Microsoft Security 23 Juli 2026 om 10:06 Information published.
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root Microsoft Security 23 Juli 2026 om 10:06 Information published.
CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. Microsoft Security 23 Juli 2026 om 10:05 Information published.
CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. Microsoft Security 23 Juli 2026 om 10:05 Information published.
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering Microsoft Security 23 Juli 2026 om 10:05 Information published.
CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files Microsoft Security 23 Juli 2026 om 10:05 Information published.