Reading view
Chromium: CVE-2026-4450 Out of bounds write in V8
CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability
Chromium CVE-2026-87536: Use after free in V8
CVE-2026-88097 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
Chromium: CVE-2026-0899 Out of bounds memory access in V8
CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability
CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-78501 Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85917 Azure AI Foundry Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62874 Azure Billing Elevation of Privilege Vulnerability
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.