Search Results (948 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-69843 1 Microsoft 1 Microsoft Fabric 2026-09-17 10 Critical
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85878 1 Microsoft 1 Azure Horizondb 2026-09-17 9.9 Critical
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVE-2026-62874 1 Microsoft 1 Azure Billing 2026-09-17 10 Critical
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85889 1 Microsoft 1 Azure Ai Foundry 2026-09-17 10 Critical
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70200 1 Microsoft 1 Azure Logic Apps 2026-09-17 10 Critical
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-87701 1 Microsoft 1 Cosmos Db 2026-09-17 9.6 Critical
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
CVE-2026-83944 1 Microsoft 1 Azure Logic Apps 2026-09-17 10 Critical
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85885 1 Microsoft 1 365 Copilot 2026-09-17 9.9 Critical
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVE-2026-69399 1 Microsoft 1 Azure Arc 2026-09-17 10 Critical
Azure Arc Elevation of Privilege Vulnerability
CVE-2026-77903 1 Microsoft 1 Dataverse 2026-09-17 9 Critical
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69865 1 Microsoft 1 Azure Container Registry 2026-09-17 10 Critical
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70009 1 Microsoft 1 Azure Arc 2026-09-17 9.3 Critical
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-72979 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more 2026-09-17 9.8 Critical
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-73009 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-17 9.8 Critical
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVE-2026-73010 1 Microsoft 6 Windows 10 1809, Windows Server 2019, Windows Server 2019 (server Core Installation) and 3 more 2026-09-17 9.8 Critical
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
CVE-2026-73025 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 11 more 2026-09-17 9.8 Critical
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-67643 1 Microsoft 6 Microsoft Sql Server 2022 (cu 26), Microsoft Sql Server 2022 (gdr), Microsoft Sql Server 2025 (cu8) and 3 more 2026-09-17 9.8 Critical
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67636 1 Microsoft 3 Sql Server 2019, Sql Server 2022, Sql Server 2025 2026-09-17 9 Critical
Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67378 1 Microsoft 6 Microsoft Sql Server 2019 (gdr), Microsoft Sql Server 2022 (gdr), Microsoft Sql Server 2025 For X64-based Systems (gdr) and 3 more 2026-09-17 9 Critical
Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67631 1 Microsoft 4 Sql Server 2017, Sql Server 2019, Sql Server 2022 and 1 more 2026-09-17 9.8 Critical
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.