CVE-2026-83941
- EPSS 0.73%
- Veröffentlicht 08.09.2026 17:10:36
- Zuletzt bearbeitet 16.09.2026 13:04:10
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVE-2026-62916
- EPSS 0.58%
- Veröffentlicht 03.09.2026 22:59:17
- Zuletzt bearbeitet 08.09.2026 16:50:35
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
- EPSS -
- Veröffentlicht 20.08.2026 21:43:12
- Zuletzt bearbeitet 25.08.2026 16:08:43
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVE-2026-69851
- EPSS -
- Veröffentlicht 20.08.2026 21:43:12
- Zuletzt bearbeitet 25.08.2026 16:09:10
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2026-62869
- EPSS 0.41%
- Veröffentlicht 11.08.2026 17:07:24
- Zuletzt bearbeitet 13.08.2026 12:20:48
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
- EPSS 0.3%
- Veröffentlicht 22.05.2026 22:04:40
- Zuletzt bearbeitet 23.07.2026 11:10:00
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-33843
- EPSS 0.47%
- Veröffentlicht 22.05.2026 22:03:10
- Zuletzt bearbeitet 23.07.2026 11:10:00
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-40379
- EPSS 0.91%
- Veröffentlicht 12.05.2026 16:58:10
- Zuletzt bearbeitet 21.05.2026 18:48:48
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
- EPSS 0.51%
- Veröffentlicht 23.04.2026 21:37:42
- Zuletzt bearbeitet 28.04.2026 12:10:53
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-24305
- EPSS 0.5%
- Veröffentlicht 22.01.2026 22:47:36
- Zuletzt bearbeitet 03.02.2026 12:46:12
Azure Entra ID Elevation of Privilege Vulnerability