Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 26 min 41 sec ago

CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-62918 Microsoft Teams Spoofing Vulnerability

Thu, 08/06/2026 - 14:00
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability

Thu, 08/06/2026 - 14:00
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability

Thu, 08/06/2026 - 14:00
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability

Thu, 08/06/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

Pages