PatchSiren

Microsoft CVE debriefs · Page 49

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Microsoft CVE published 2026-07-03

CVE-2026-57981

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-03T21:17:01.313Z and has not been modified since then. This use-after-free vulnerability in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network, posing a high risk due to its high CVSS score of 8.8. Users of Microsoft Edge (Chromium-based) should apply patc [truncated]

HIGH Microsoft CVE published 2026-07-03

CVE-2026-57977

CVE-2026-57977 is a high-severity vulnerability in Microsoft Edge (Chromium-based) that allows unauthorized attackers to perform spoofing over a network by improper neutralization of input during web page generation, also known as cross-site scripting. This vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. It exists in the Microsoft Edge (Chromium-based) browser and allows an unaut [truncated]

HIGH Microsoft CVE published 2026-07-03

CVE-2026-57975

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-03T21:17:01.077Z and has not been modified since then. This type confusion vulnerability in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Users should prioritize patching to prevent potential code execution attacks. The vulnerability has a CVSS score [truncated]

HIGH Microsoft CVE published 2026-07-03

CVE-2026-57974

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-03T21:17:00.957Z and has not been modified since then. This integer overflow or wraparound vulnerability in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Users of Microsoft Edge (Chromium-based) should review and apply patches from Microsoft as necessary.

MEDIUM Microsoft CVE published 2026-07-03

CVE-2026-56646

CVE-2026-56646 is a MEDIUM severity vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized attacker to perform spoofing over a network. The vulnerability has a CVSS score of 6.5 and was published on 2026-07-03T21:17:00.783Z. This vulnerability is caused by the exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based). The vulnerability allows an un [truncated]

HIGH Microsoft CVE published 2026-07-03

CVE-2026-56645

The CVE-2026-56645 vulnerability is a heap-based buffer overflow in Microsoft Edge (Chromium-based), which allows an unauthorized attacker to execute code over a network. This vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Users of Microsoft Edge (Chromium-based) should prioritize patching to prevent potential code execution attacks. The CVE record was published on 2026-07-03T21 [truncated]

MEDIUM Microsoft CVE published 2026-07-03

CVE-2026-55945

CVE-2026-55945 is a race condition vulnerability in Microsoft Edge (Chromium-based) that allows an authorized attacker to disclose information locally. The vulnerability has a CVSS score of 4.2 and a severity of MEDIUM. Microsoft Edge (Chromium-based) is affected by this vulnerability. The vulnerability is caused by a race condition that allows an authorized attacker to disclose information locally. Users [truncated]

MEDIUM Microsoft CVE published 2026-07-03

CVE-2026-45488

CVE-2026-45488 is a medium-severity vulnerability in Microsoft Edge (Chromium-based) that allows an unauthorized attacker to perform spoofing over a network. The vulnerability has a CVSS score of 5.4 and is classified as CWE-451. This type of vulnerability can lead to user interface misrepresentation of critical information, potentially allowing attackers to deceive users into performing unintended action [truncated]

CRITICAL Microsoft CVE published 2026-07-02

CVE-2026-57100

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-02T23:16:51.267Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This critical server-side request forgery (SSRF) vulnerability in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Security teams [truncated]

HIGH Microsoft CVE published 2026-07-02

CVE-2026-54998

CVE-2026-54998 is a high-severity vulnerability in Microsoft Exchange Online that allows an authorized attacker to elevate privileges over a network. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. It is caused by incorrect authorization in Microsoft Exchange Online. Organizations using Microsoft Exchange Online should prioritize patching this vulnerability to prevent potential privil [truncated]

CRITICAL Microsoft CVE published 2026-07-02

CVE-2026-45499

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-02T23:16:51.003Z and has not been modified since then. This server-side request forgery (SSRF) vulnerability in Azure OpenAI allows an authorized attacker to elevate privileges over a network, with a CVSS score of 9.9 and classified as CRITICAL. Security teams should assess and mitigate this vulnerability.

CRITICAL Microsoft CVE published 2026-07-02

CVE-2026-41106

CVE-2026-41106 is a Url redirection to untrusted site ('open redirect') vulnerability in M365 Copilot with a CVSS score of 9.3 and a severity of CRITICAL. The vulnerability allows an unauthorized attacker to elevate privileges over a network. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. The weakness is CWE-601. Security teams and administrators responsible for M365 Copilot should be aw [truncated]

MEDIUM Microsoft CVE published 2026-07-02

CVE-2026-26145

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-02T23:16:49.813Z and has not been modified since then. This medium-severity vulnerability in Azure Synapse, caused by improper access control, allows an authorized attacker to elevate privileges over a network. Defenders should verify configurations and monitor for unusual activity.

Known exploited Microsoft CVE published 2026-07-01

CVE-2026-45659

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability. This high-severity issue could allow an attacker to execute arbitrary code on the affected system. Defenders should assess exposure and prioritize patching or mitigations. The vulnerability is known to be exploited in the wild, and CISA has provided guidance for prioritization and forensics triage. Affected product deployments sh [truncated]

MEDIUM Microsoft CVE published 2026-06-19

CVE-2026-50519

CVE-2026-50519 is a medium-severity vulnerability (CVSS score of 6.5) affecting GitHub Copilot and Visual Studio Code. The vulnerability allows an unauthorized attacker to disclose information over a network due to the initialization of a resource with an insecure default. This CVE was published on June 19, 2026, and has not been modified since its publication. The affected product and vendor are not expl [truncated]

CRITICAL Microsoft CVE published 2026-06-19

CVE-2026-48582

CVE-2026-48582 is a critical vulnerability in Microsoft Exchange Online that allows an authorized attacker to elevate privileges over a network. The vulnerability has a CVSS score of 9.6 and is classified as CRITICAL. The issue was published on June 19, 2026, and defenders should prioritize patching to limit exposure. This vulnerability affects Microsoft Exchange Online, and defenders should verify the af [truncated]

HIGH Microsoft CVE published 2026-06-19

CVE-2026-47645

CVE-2026-47645 is a high-severity open redirect vulnerability in Microsoft 365 Copilot's Business Chat. The CVSS score is 8.8, indicating a significant risk. The vulnerability allows an unauthorized attacker to elevate privileges over a network. Microsoft 365 Copilot users are potentially exposed. The CVE was published on June 19, 2026, and no changes have been made since then. Defenders should prioritize [truncated]

MEDIUM Microsoft CVE published 2026-06-19

CVE-2026-42895

CVE-2026-42895 is a medium-severity vulnerability in Microsoft Copilot, allowing unauthorized attackers to perform tampering over a network via command injection. The vulnerability has a CVSS score of 6.5. Microsoft Copilot users may be exposed if they haven't applied mitigations. The priority posture for defenders is to verify and apply official patches promptly.

CRITICAL Microsoft CVE published 2026-06-18

CVE-2026-47647

CVE-2026-47647 is a critical vulnerability in Microsoft Dynamics 365 that allows an authorized attacker to elevate privileges over a network. This improper access control vulnerability has a CVSS score of 9.9 and is considered critical. The vulnerability was published on June 18, 2026, and has not been modified since. Microsoft Dynamics 365 users should take immediate action to mitigate this vulnerability [truncated]

HIGH Microsoft CVE published 2026-06-18

CVE-2026-47633

CVE-2026-47633 is a HIGH-severity vulnerability (CVSS score 7.5) that allows unauthorized disclosure of sensitive information over a network in Cost Management Interactive Experiences. Published on June 18, 2026, by the CVE Program, this vulnerability is attributed to an unknown vendor, possibly Microsoft, based on limited evidence. The vulnerability enables attackers to access sensitive data without auth [truncated]

HIGH Microsoft CVE published 2026-06-18

CVE-2026-32174

CVE-2026-32174 is a HIGH-severity vulnerability in Azure Bot Service, allowing authorized attackers to elevate privileges over a network due to improper authentication. This issue was published on June 18, 2026. Organizations using Azure Bot Service should review and update their configurations to prevent potential exploitation. Microsoft is the likely vendor, although confirmation is needed. The CVE reco [truncated]

HIGH Microsoft CVE published 2026-06-16

CVE-2026-50656

CVE-2026-50656 is an elevation of privilege vulnerability in the Microsoft Malware Protection Engine in Microsoft Defender, publicly referred to as 'RoguePlanet'. Microsoft is aware of this vulnerability and is working to provide a high-quality security update to address it. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-8863

CVE-2026-8863 is a HIGH severity vulnerability with a CVSS score of 7.8. Multiple Microsoft-signed UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. A specific UEFI DBX [truncated]

HIGH Microsoft CVE published 2026-06-09

CVE-2026-50512

CVE-2026-50512 is a HIGH-severity vulnerability with a CVSS score of 7.8. It involves improper link resolution before file access, also known as 'link following,' in Microsoft PC Manager. This vulnerability allows an authorized attacker to elevate privileges locally.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-50511

CVE-2026-50511 is a HIGH-severity vulnerability (CVSS Score: 7.8) affecting Microsoft PC Manager. The vulnerability is caused by improper link resolution before file access, also known as 'link following.' An authorized attacker can exploit this vulnerability to elevate privileges locally.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-50508

CVE-2026-50508 is a vulnerability in Windows NTLM that allows an unauthorized attacker to perform spoofing over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. It was published on 2026-06-09T17:17:50.027Z and last modified on 2026-06-09T19:32:51.440Z.

MEDIUM Microsoft CVE published 2026-06-09

CVE-2026-50507

CVE-2026-50507 is a protection mechanism failure in Windows BitLocker that allows an unauthorized attacker to bypass a security feature with a physical attack. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. It was published on 2026-06-09T17:17:49.857Z and modified on 2026-06-10T16:33:09.777Z.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-49161

CVE-2026-49161 is a high-severity vulnerability in Microsoft PC Manager, with a CVSS score of 7.8. The vulnerability is caused by improper access control, allowing an authorized attacker to bypass a security feature locally. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-49161) and details can be found on [nvd](https://nvd.nist.gov/vuln/detail/CVE-2026-49161).

HIGH Microsoft CVE published 2026-06-09

CVE-2026-49160

CVE-2026-49160 is a HIGH severity vulnerability with a CVSS score of 7.5. The vulnerability is caused by uncontrolled resource consumption in HTTP/2, which allows an unauthorized attacker to deny service over a network. The vulnerability affects multiple Microsoft products, including Windows 10, Windows 11, and Windows Server.

HIGH Microsoft CVE published 2026-06-09

CVE-2026-48583

CVE-2026-48583 is a use-after-free vulnerability in the Windows Kernel. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.