6.5
CVE-2026-26136 - Microsoft Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
5.3
CVE-2026-24299 - M365 Copilot Information Disclosure Vulnerability
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
8.6
CVE-2026-23659 - Azure Data Factory Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
6.5
CVE-2026-26120 - Microsoft Bing Tampering Vulnerability
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.
8.6
CVE-2026-23658 - Azure DevOps: msazure Elevation of Privilege Vulnerability
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
9.8
CVE-2026-32191 - Microsoft Bing Images Remote Code Execution Vulnerability
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
8.6
CVE-2026-26138 - Microsoft Purview Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
8.6
CVE-2026-26139 - Microsoft Purview Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
10
CVE-2026-32169 - Azure Cloud Shell Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
6.8
CVE-2026-32747 - SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrโฆ
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source files using filepath.Abs() with no workspace boundary check, relying solely on util.IsSensitivePath() whose blocklist omits /proc/, /run/secrets/, and home directory dotfiles. An admiโฆ