Search Results (468 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-68823 1 Microsoft 1 Azure Confidential Ledger 2026-08-07 9.1 Critical
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
CVE-2026-62836 1 Microsoft 1 Azure Sql Managed Instance 2026-08-07 8.7 High
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50515 1 Microsoft 1 Azure Service Bus 2026-08-07 9.9 Critical
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVE-2026-62830 1 Microsoft 1 Azure Sre Agent 2026-08-07 9.9 Critical
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-56162 1 Microsoft 1 Azure Sql Database 2026-08-07 10 Critical
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56161 1 Microsoft 1 Azure Logic Apps 2026-08-07 9.6 Critical
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-50481 1 Microsoft 1 Azure Active Directory 2026-08-07 9.9 Critical
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2025-66390 1 Microsoft 1 Azure Api Management 2026-08-04 9.8 Critical
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words, disabling signup in the UI does not disable the underlying API endpoint (which still accepts cross-tenant requests based on the Host header). NOTE: The supplier states that they evaluated the report and determined it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation). NOTE: The supplier evaluated this report and determined that it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation).
CVE-2026-24304 1 Microsoft 1 Azure Resource Manager 2026-07-30 9.9 Critical
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-35425 1 Microsoft 1 Azure Api Management 2026-07-29 8 High
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-56167 1 Microsoft 2 Azure Ai Search, Azure Ai Search 2026-07-27 8.5 High
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
CVE-2026-62835 1 Microsoft 1 Azure Portal 2026-07-25 9.3 Critical
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-58630 1 Microsoft 1 Azure App Service 2026-07-24 10 Critical
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275 1 Microsoft 1 Azure Dns 2026-07-24 10 Critical
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825 1 Microsoft 1 Azure Key Vault 2026-07-24 10 Critical
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56160 1 Microsoft 1 Azure Red Hat Openshift 2026-07-24 9.1 Critical
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVE-2026-56163 1 Microsoft 1 Azure Kubernetes Service 2026-07-24 10 Critical
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50653 1 Microsoft 3 .net, .net Framework, Azure Active Directory 2026-07-22 7.5 High
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-50652 1 Microsoft 3 .net, .net Framework, Azure Active Directory 2026-07-22 7.5 High
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-57969 1 Microsoft 1 Azure Cyclecloud 2026-07-15 8.8 High
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.