Microsoft Security Center Center News

Subscribe to Microsoft Security Center Center News feed
Updated: 37 min 44 sec ago

CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69558 Microsoft Partner Center Information Disclosure Vulnerability

Thu, 08/20/2026 - 14:00

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability

Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

Categories: Microsoft

CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability

Thu, 08/20/2026 - 14:00

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

Categories: Microsoft

CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

Thu, 08/20/2026 - 14:00
Added clarifying information to the mitigation. This is an informational change only.
Categories: Microsoft

CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability

Wed, 08/19/2026 - 14:00
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Categories: Microsoft

CVE-2021-26859 Microsoft Power BI Information Disclosure Vulnerability

Wed, 08/19/2026 - 14:00
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Categories: Microsoft

CVE-2021-41372 Power BI Report Server Spoofing Vulnerability

Wed, 08/19/2026 - 14:00
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Categories: Microsoft

CVE-2023-21806 Power BI Report Server Spoofing Vulnerability

Wed, 08/19/2026 - 14:00
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Categories: Microsoft

CVE-2024-43612 Power BI Report Server Spoofing Vulnerability

Wed, 08/19/2026 - 14:00
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Categories: Microsoft

CVE-2024-43481 Power BI Report Server Spoofing Vulnerability

Wed, 08/19/2026 - 14:00
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Categories: Microsoft

CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability

Tue, 08/18/2026 - 14:00

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Categories: Microsoft

Chromium: CVE-2026-19560 Use after free in Blink

Fri, 08/14/2026 - 23:37
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-19559 Use after free in HTML

Fri, 08/14/2026 - 23:37
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-19558 Use after free in Extensions

Fri, 08/14/2026 - 23:37
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-19557 Use after free in TabStrip

Fri, 08/14/2026 - 23:37
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

Chromium: CVE-2026-19556 Use after free in V8

Fri, 08/14/2026 - 23:37
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information.
Categories: Microsoft

CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fri, 08/14/2026 - 14:00

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Categories: Microsoft

Pages