Vulnerabilities
28 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66302 | Critical unauthenticated file-path RCE in Microsoft Skype for Business CVE-2026-66302 is a critical (CVSS 9.8) vulnerability in Microsoft Skype for Business in which an external attacker controls the file name or path used by the software (CWE-73, external control of file name or path). The flaw is exploitable over a network with no authentication, no privileges, and no user interaction, so a remote unauthenticated attacker who can reach the affected Skype for Business service can trigger it. Successful exploitation yields remote code execution on the target, with high impact on confidentiality, integrity, and availability. Any organization running the affected Skype for Business deployment, presumably the on-premises Skype for Business server product, is affected; the available data does not specify the exact affected version ranges. No public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and EPSS assigns roughly a 0.5% probability of exploitation in the next 30 days, so no exploitation is currently known. Do: Apply Microsoft's September 2026 Patch Tuesday updates for Skype for Business as soon as testing permits, since the fix is delivered through that release. Until patched, restrict network access to Skype for Business services (for example, firewall or VPN rules limiting who can reach the server), and identify any Skype for Business endpoints exposed to the internet for prioritized patching and monitoring. Check vendor advisory pages for the specific affected and fixed version numbers for your deployment. | 9.8 | <1% |
| largelikely tens of thousands of on-premises Skype for Business servers across thousands of organizations (estimated; Microsoft publishes no current install counts) | ||
| CVE-2026-81376 | Security Feature Bypass in Microsoft Visual Studio Code CVE-2026-81376 is a critical security feature bypass in Microsoft Visual Studio Code caused by an incomplete comparison with missing factors (CWE-1023), resulting in a protection mechanism failure (CWE-693). The flaw is reachable over a network and exploitation requires user interaction (per the CVSS vector), such as inducing a user to act on attacker-controlled content, after which an unprivileged attacker can bypass the affected security check. The changed-scope metric indicates the bypass can cross a component boundary, and the high confidentiality, integrity and availability ratings mean a successful bypass can have serious consequences beyond weakening a single control. Everyone running Visual Studio Code is potentially affected; the available data does not specify the vulnerable version ranges or the fixing release. Exploitation has not been observed: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.7% chance of exploitation in the next 30 days. Do: Monitor Microsoft's advisory for the fixed release and update Visual Studio Code as soon as a patched version is published, since no version numbers are available yet. Until then, exercise caution with untrusted files, repositories and prompts (user interaction is part of the attack vector), and prioritize scheduling the update given the 9.6 critical CVSS despite no known exploitation. | 9.6 | <1% |
| massTens of millions of users (VS Code is the most widely used code editor, with roughly 70%+ usage share among professional developers) | ||
| CVE-2026-78510 +1 in the same advisory: …78509 | Critical heap buffer overflow in Microsoft Word enables remote code execution CVE-2026-78510 is a heap-based buffer overflow (CWE-122) in Microsoft Office Word that, per the CVSS vector, is reachable over a network without authentication, without user interaction, and without any special privileges. A memory-corruption condition in Word's processing can be triggered by an attacker who can reach the vulnerable component, causing a heap overflow that disrupts memory layout. Successful exploitation allows the attacker to execute arbitrary code in the context of the Word process, with high impact on confidentiality, integrity, and availability. Organizations running Word within Microsoft 365 Apps or perpetual Office 2016, 2019, 2021, or 2024 are in scope; specific affected build numbers are not stated in the available data and should be taken from Microsoft's advisory. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a ~1% probability of exploitation within 30 days. Do: Inventory endpoints for Microsoft 365 Apps and perpetual Office 2016/2019/2021/2024 installations and apply Microsoft's Word security updates for all affected versions as soon as they are published, prioritizing internet-reachable or document-processing-heavy systems given the network-exploitable, no-authentication CVSS vector. Until patched, verify that Office automatic updates are enabled and consider limiting exposure for high-risk hosts. Because there is no public PoC or known exploitation, treat this as high-priority patching rather than an active-incident response, and re-check KEV/EPSS for movement. | 9.8 | <1% |
| masshundreds of millions of users (Office/Microsoft 365 installed base exceeds 1 billion devices and several hundred million commercial seats) | ||
| CVE-2026-78445 | Use-after-free RCE in Windows Services for NFS ONCRPC XDR Driver CVE-2026-78445 is a use-after-free vulnerability (CWE-416) in the ONCRPC XDR driver that is part of Windows Services for NFS, Microsoft's optional Network File System interoperability component. An unauthenticated remote attacker can trigger the flaw by sending network traffic that is processed by the driver's ONCRPC/XDR handling, causing reuse of freed memory and resulting in arbitrary code execution. Successful exploitation grants the attacker code execution on the target host with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 9.8, critical). Only Windows systems where the optional Services for NFS feature has been installed and enabled are exposed, since it is not part of a default Windows installation. As of now there is no known exploitation in the wild, no public proof-of-concept, and the issue is not in CISA KEV; EPSS estimates roughly a 0.9% probability of exploitation within the next 30 days. Do: Inventory Windows hosts for the Services for NFS optional features (Client for NFS / Server for NFS) and for active NFS-related services and listeners (e.g., NFS on port 2049, ONCRPC portmapper on port 111), and prioritize those systems for Microsoft's patch for CVE-2026-78445 once released, as specific affected builds are not enumerated in the available data. As interim mitigation, disable or remove Services for NFS on systems that do not need it, or restrict network access to the NFS/ONCRPC endpoints to trusted hosts only. No public exploit is known, so there is no indication of in-the-wild exploitation at this time. | 9.8 | <1% |
| large~10,000-100,000 Windows hosts with Services for NFS enabled (exact count unknown) | ||
| CVE-2026-69525 | Use-After-Free RCE in Windows Remote Desktop Services CVE-2026-69525 is a use-after-free memory corruption flaw (CWE-416) in Windows Remote Desktop Services, rated critical at CVSS 9.8. Per the CVSS vector, a remote, unauthenticated attacker can reach the vulnerable code path over the network with no privileges and no user interaction, presumably by sending crafted input to the RDP/RDS service. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability. Any Windows system running Remote Desktop Services is affected, and organizations exposing RDP (TCP 3389) to the internet are the primary concern, since public scans show millions of such endpoints. There is no public proof-of-concept or CISA KEV listing yet, and EPSS estimates a ~1.1% (63rd percentile) chance of exploitation within 30 days; the fix shipped as part of Microsoft's record 974-CVE Patch Tuesday, which separately included two exploited Windows zero-days and 20 wormable bugs. Do: Apply Microsoft's security update for CVE-2026-69525 as soon as possible, prioritizing hosts with RDP (TCP 3389) reachable from untrusted networks. Until patched, restrict RDP exposure via firewall rules, VPN, or RD Gateway, and enable Network Level Authentication as a precaution. Inventory internet-facing systems for exposed RDP listeners and monitor for exploitation activity. | 9.8 | 1% |
| mass~3-4 million internet-exposed RDP endpoints (per public internet-wide scans); millions more reachable internally | ||
| CVE-2026-80098 | Signature Verification Flaw Allows Privilege Escalation in Microsoft Copilot Studio Microsoft Copilot Studio, the low-code cloud service in the Power Platform used to build AI copilots and agents, fails to properly verify cryptographic signatures on certain network traffic (CWE-347), allowing signature checks to be bypassed. An unauthenticated attacker can trigger the flaw remotely over a network with no user interaction by sending a crafted request whose signature is accepted without correct verification. Successful exploitation elevates the attacker's privileges, and the changed-scope CVSS metric plus high confidentiality, integrity, and availability ratings indicate impact that extends beyond the immediate component. Because Copilot Studio is a multi-tenant Microsoft-hosted service, every organization using the service falls within the blast radius, and there are no on-premises versions to inventory. As of the September 2026 Patch Tuesday disclosure, no in-the-wild exploitation is known, there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a modest 0.3% probability of exploitation within 30 days. Do: Because Copilot Studio is a Microsoft-managed SaaS offering, there is no customer-side patch to install; verify via the Microsoft 365 admin center (message center and service health) that the September 2026 service update has been applied to your tenant. In the meantime, review tenant audit logs for anomalous privilege changes or unexpected agent activity, and scrutinize the permissions and authentication settings of any agents exposed to unauthenticated users. Follow Microsoft's advisory for the CVE in case compensating controls or configuration guidance are provided. | 10.0 | <1% |
| masslikely millions of users across on the order of 100,000+ organizations (multi-tenant Microsoft 365/Power Platform SaaS with no per-install counts) | ||
| CVE-2026-65818 | Critical SSRF Privilege Escalation in Microsoft Power Automate (Power Platform) Server-side request forgery (CWE-918) in Microsoft Power Automate, part of Microsoft Power Platform, lets a low-privileged authenticated user cause the service to make network requests to internal or attacker-influenced endpoints. With network attack vector, low privileges required, no user interaction, and a changed scope with high confidentiality, integrity and availability impact (CVSS 9.9), the SSRF can be leveraged to reach internal services and elevate the attacker's privileges beyond their normal user role. Any organization whose tenants use Power Automate flows is exposed, since exploitation requires only a valid low-privilege account with network access to the service. There is no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS assigns a 0.3% 30-day exploitation probability (27th percentile), indicating limited near-term risk. Do: Verify remediation through Microsoft's MSRC advisory for CVE-2026-65818: the Power Automate cloud service is patched server-side, so confirm your tenant has received the update and patch any separately installed components (e.g., Power Automate Desktop or the on-premises data gateway) if the advisory lists them as affected. Review Power Automate flow and connector permissions and DLP policies, and monitor for unexpected privilege changes or anomalous outbound requests from the service. With no public PoC, KEV listing, or known exploitation, standard prioritization within your normal patch cycle is reasonable. | 9.9 | <1% |
| massmillions of users (Power Automate spans millions of monthly active users within Microsoft 365/Dynamics 365 estates) | ||
| CVE-2026-62916 | Authentication Bypass in Microsoft Entra ID Enables Privilege Elevation CVE-2026-62916 is an authentication bypass (CWE-288) in Microsoft Entra ID, Microsoft's cloud identity and access management service, in which an alternate path or channel allows authentication checks to be circumvented. Per the CVSS vector, it is exploitable remotely over a network with no privileges and no user interaction required, by authenticating via an alternate path instead of the standard sign-in flow. A successful unauthenticated attacker gains the ability to elevate privileges, with high impact on confidentiality, integrity, and availability reflected in the 9.8 critical score. The affected population includes organizations relying on Entra ID, which is the default identity platform for Microsoft 365, Azure, and hybrid deployments; the available data does not specify affected versions or the specific sub-component involved. There is no public proof-of-concept, no confirmed in-the-wild exploitation, and the CVE is not in CISA's KEV; EPSS assigns a 0.6% probability of exploitation within 30 days. Do: Since Entra ID is a cloud service patched centrally by Microsoft, verify that the September 2026 security updates have been applied to your tenant and follow the Microsoft advisory for any tenant-side configuration or conditional access actions; no workarounds are documented in the available data. Review Entra ID sign-in and audit logs for unexpected privileged authentication activity, and re-check exposure after any additional Microsoft guidance on affected flows. | 9.8 | <1% |
| masshundreds of millions of user identities across millions of Microsoft 365/Azure tenant organizations | ||
| CVE-2026-69502 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2026-69836 +1 in the same advisory: …69851 | Unauthenticated Deserialization RCE in Microsoft Entra ID CVE-2026-69836 is a deserialization-of-untrusted-data flaw (CWE-502) in Microsoft Entra ID, Microsoft's cloud identity and access management service. An unauthenticated attacker can trigger it by sending crafted serialized data over the network, and the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) confirms that no privileges or user interaction are required. Successful exploitation yields remote code execution with high impact to confidentiality, integrity, and availability, and the changed-scope rating indicates impact can extend beyond the initially affected component. Any organization whose sign-in or identity infrastructure relies on Microsoft Entra ID is potentially in scope, although the source data publishes no specific affected version ranges. There is no known public proof-of-concept, the flaw is not in CISA's KEV, EPSS assigns a 1.6% probability of exploitation within 30 days, and related headlines indicate Microsoft has already patched the issue. Do: Because Entra ID is a Microsoft-operated cloud service, there is no on-premises patch to apply; consult Microsoft's advisory to confirm the fix has rolled out to your tenant and whether any tenant-level action is required. Review Entra ID sign-in logs, audit logs, and application registrations for anomalies consistent with pre-authentication exploitation, and monitor Microsoft's advisory and CISA KEV for status changes. | 10.0 group max | 2% |
| masshundreds of millions of users across effectively all Microsoft 365/Azure tenants (on the order of millions of organizations) | ||
| CVE-2026-69555 | Incorrect Authorization in Microsoft Azure Arc Enables Network Privilege Escalation Microsoft Azure Arc, the service used to manage on-premises and multi-cloud servers from Azure, contains an incorrect authorization flaw (CWE-863) in which permission checks fail to properly restrict what an unauthorized party may do. Per the CVSS vector, the flaw is exploitable over a network with no privileges or user interaction required, and exploitation changes the security scope, allowing an unauthorized attacker to elevate privileges with high impact on confidentiality and integrity. Any organization that has enrolled servers or other resources with Azure Arc is potentially exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates only about a 0.4% probability of exploitation within 30 days. Do: Apply Microsoft's fix as soon as it is released (expected with the September 2026 Patch Tuesday updates) and check Microsoft's advisory for affected Azure Arc components and agent versions. Until then, review and minimize permissions granted to Arc-enabled resources and restrict network reachability to Arc management endpoints. Monitor Microsoft's advisories for updated agent packages and redeploy them promptly to enrolled servers. | 10.0 | <1% |
| mass≈1M+ Arc-enabled servers (Azure Arc is Microsoft's broadly deployed hybrid/multi-cloud management service) | ||
| CVE-2026-69400 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.6 | <1% |
| — | ||
| CVE-2026-68782 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges o Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.9 group max | <1% |
| — | ||
| CVE-2026-65816 | Unauthenticated Privilege Elevation Flaw in Microsoft Azure Arc Microsoft Azure Arc contains a use of incorrectly-resolved name or reference (CWE-706) that allows an unauthorized, unauthenticated attacker to elevate privileges over a network. The flaw is triggered through network access alone, with no privileges, user interaction, or complex conditions required, as reflected in its maximum CVSS 3.1 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The scope-changed metric indicates the attack crosses a security boundary, so an attacker who reaches the vulnerable component could gain elevated privileges with high impact on confidentiality, integrity, and availability. Organizations that have enrolled on-premises or multicloud resources into Azure Arc are affected; the source data provides no specific affected version ranges, and the CPE product entry also references Azure Web Apps while the description names Azure Arc. There is currently no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.5% 30-day exploitation probability (43rd percentile), indicating no confirmed in-the-wild exploitation. Do: No fixed version numbers are included in the source data, so consult Microsoft's advisory and the September 2026 Patch Tuesday release for the Azure Arc update and apply it promptly when published. In the meantime, inventory Azure Arc-enabled servers and other enrolled resources, restrict network exposure of Arc agent and management endpoints to trusted management paths, and monitor Microsoft's advisory for changes to exploitation status. Given the maximum CVSS score but no PoC or KEV listing yet, treat this as a high-priority patch rather than an emergency, and escalate if Microsoft confirms active exploitation. | 10.0 | <1% |
| large≈ hundreds of thousands of Arc-enrolled machines across enterprise tenants (deployment-pattern estimate; exact counts not in source data) | ||
| CVE-2026-65801 | SSRF Privilege Elevation in Microsoft Exchange Online CVE-2026-65801 is a server-side request forgery (CWE-918) in Microsoft's cloud-hosted Exchange Online service that an unauthorized attacker can reach over the network without credentials or user interaction. A crafted request causes Exchange Online server components to issue requests toward internal service endpoints, and the scope-changed CVSS 3.1 vector (S:C with high confidentiality, integrity, and availability impact) indicates the resulting privilege elevation extends beyond the initially targeted component. A successful attacker gains elevated privileges within the Exchange Online service, potentially enabling broader access to mailbox data and service functionality. All organizations with mailboxes hosted in Exchange Online are in scope; because this is a flaw in Microsoft's managed service, customers cannot patch it themselves and depend on Microsoft's service-side remediation. Exploitation has not been publicly confirmed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only about a 0.5% probability of exploitation within 30 days. Do: Monitor the MSRC advisory for CVE-2026-65801 and the Microsoft 365 admin center Message Center for Microsoft's service-side fix and remediation timeline; no customer-side patch or version upgrade applies. Until remediation is confirmed, review Exchange Online audit logs (Unified Audit Log) for anomalous privilege changes or unusual server-side activity, and report any suspected exploitation to MSRC. | 10.0 | <1% |
| masshundreds of millions of mailboxes across Microsoft 365 tenants (the entire hosted Exchange Online service is in scope) | ||
| CVE-2026-65770 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacke Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2026-62834 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.8 | <1% |
| — |