5.3
CVE-2026-8112 - 8421bit MiniClaw kernel.ts executeCognitivePulse os command injection
A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the file src/kernel.ts. Performing a manipulation results in os command injection. It is possible to initiate the attack remotely. The exploit has been madโฆ
10
CVE-2026-42826 - Azure DevOps Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
9.6
CVE-2026-35428 - Azure Cloud Shell Spoofing Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
8.6
CVE-2026-35435 - Azure AI Foundry Elevation of Privilege Vulnerability
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
8.2
CVE-2026-34327 - Microsoft Partner Center Spoofing Vulnerability
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.
9
CVE-2026-33844 - Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
9.6
CVE-2026-33823 - Microsoft Team Events Portal Information Disclosure Vulnerability
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
8.8
CVE-2026-32207 - Azure Machine Learning Notebook Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
9.9
CVE-2026-33109 - Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
7.5
CVE-2026-33111 - Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.