CVE-2026-68789 Microsoft
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Azure SQL Database
Updated August 20, 2026
CVE-2026-69400 Microsoft
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS 9.6
Update availability Patch status unknown Affected: Azure Logic Apps
Updated August 20, 2026
CVE-2026-69419 Microsoft
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
CVSS 8.5
Update availability Patch status unknown Affected: Azure Data Manager for Energy
Updated August 20, 2026
CVE-2026-69502 Microsoft
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure SQL Database
Updated August 20, 2026
CVE-2026-69519 Microsoft
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
CVSS 8.6
Update availability Patch status unknown Affected: Azure Stack HCI
Updated August 20, 2026
CVE-2026-69543 Microsoft
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
CVSS 8.5
Update availability Patch status unknown Affected: Azure Virtual Machines
Updated August 20, 2026
CVE-2026-69555 Microsoft
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure ARC
Updated August 20, 2026
CVE-2026-69558 Microsoft
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
CVSS 8.6
Update availability Patch status unknown Affected: Microsoft Partner Center
Updated August 20, 2026
CVE-2026-69851 Microsoft
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Microsoft Entra ID
Updated August 20, 2026
CVE-2026-69855 Microsoft
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
CVSS 7.7
Update availability Patch status unknown Affected: Microsoft Copilot in Azure
Updated August 20, 2026
CVE-2026-71331 Microsoft
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
CVSS 8.1
Update availability Security update available Affected: Windows 10 Version 1809 for 32-bit Systems · Windows 10 Version 1809 for x64-based Systems · +6 more
Updated August 20, 2026
CVE-2026-65791 Microsoft
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +14 more
Updated August 18, 2026
CVE-2026-55040 Microsoft
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVSS 9.1
Update availability Security update available Affected: Microsoft SharePoint Enterprise Server 2016 · Microsoft SharePoint Server 2019 · +1 more
Updated July 14, 2026
CVE-2026-56188 Microsoft
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +25 more
Updated August 17, 2026
CVE-2026-63513 Microsoft
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated August 17, 2026
CVE-2026-63518 Microsoft
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated August 17, 2026
CVE-2026-63519 Microsoft
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +9 more
Updated August 17, 2026
CVE-2026-66807 Microsoft
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +9 more
Updated August 17, 2026
CVE-2026-68325 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0
Updated August 14, 2026
CVE-2026-68214 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0
Updated August 14, 2026
CVE-2026-68153 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0
Updated August 14, 2026
CVE-2026-68377 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0
Updated August 14, 2026
CVE-2026-68146 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0
Updated August 14, 2026
CVE-2026-68212 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 9.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.143.1-1 on Azure Linux 3.0
Updated August 14, 2026