CVE-2026-56162 Microsoft
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure SQL Database
Updated August 6, 2026
CVE-2026-59115 Microsoft
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Microsoft Entra Provisioning Service
Updated August 6, 2026
CVE-2026-62830 Microsoft
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Azure SRE Agent
Updated August 6, 2026
CVE-2026-62836 Microsoft
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
CVSS 8.7
Update availability Patch status unknown Affected: Azure SQL Managed Instance
Updated August 6, 2026
CVE-2026-62869 Microsoft
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Microsoft Entra ID
Updated August 6, 2026
CVE-2026-62873 Microsoft
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
CVSS 9.8
Update availability Patch status unknown Affected: Microsoft 365 Admin Center
Updated August 6, 2026
CVE-2026-62896 Microsoft
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVSS 9.6
Update availability Patch status unknown Affected: Microsoft Teams
Updated August 6, 2026
CVE-2026-62918 Microsoft
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
CVSS 7.5
Update availability Patch status unknown Affected: Microsoft Teams
Updated August 6, 2026
CVE-2026-63522 Microsoft
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
CVSS 7.8
Update availability Patch status unknown Affected: Azure SQL Database
Updated August 6, 2026
CVE-2026-65667 Microsoft
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Microsoft Teams
Updated August 6, 2026
CVE-2026-65668 Microsoft
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
CVSS 8.8
Update availability Patch status unknown Affected: Microsoft Purview eDiscovery
Updated August 6, 2026
CVE-2026-68823 Microsoft
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
CVSS 9.1
Update availability Patch status unknown Affected: Azure Confidential Ledger
Updated August 6, 2026
CVE-2026-70332 Microsoft
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVSS 9.6
Update availability Patch status unknown Affected: Microsoft SharePoint Online
Updated August 6, 2026
CVE-2026-55129 Microsoft
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS 7.8
Update availability Security update available Affected: Microsoft 365 Apps for Enterprise for 32-bit Systems · Microsoft 365 Apps for Enterprise for 64-bit Systems · +11 more
Updated July 30, 2026
CVE-2026-66803 Microsoft
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure Cosmos DB
Updated July 30, 2026
CVE-2026-56159 Microsoft
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVSS 9.8
Update availability Security update available Affected: Windows 10 Version 1607 for 32-bit Systems · Windows 10 Version 1607 for x64-based Systems · +13 more
Updated July 27, 2026
CVE-2026-48561 Microsoft
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
CVSS Not supplied
Update availability Patch status unknown Affected: Microsoft Edge Copilot for Android · Microsoft Edge Copilot for IOS
Updated July 24, 2026
CVE-2026-62835 Microsoft
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVSS 9.3
Update availability Patch status unknown Affected: Azure Portal
Updated July 24, 2026
CVE-2026-35425 Microsoft
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVSS 8.0
Update availability Patch status unknown Affected: Azure API Management (APIM)
Updated July 23, 2026
CVE-2026-49159 Microsoft
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
CVSS 6.5
Update availability Patch status unknown Affected: Microsoft Graph
Updated July 23, 2026
CVE-2026-50517 Microsoft
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Microsoft 365 Copilot
Updated July 23, 2026
CVE-2026-54120 Microsoft
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVSS 9.9
Update availability Patch status unknown Affected: Surface Management Services
Updated July 23, 2026
CVE-2026-56160 Microsoft
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVSS Not supplied
Update availability Patch status unknown Affected: Azure Red Hat OpenShift (ARO)
Updated July 23, 2026
CVE-2026-56163 Microsoft
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVSS 10.0
Update availability Patch status unknown Affected: Azure Kubernetes Service
Updated July 23, 2026