CVE-2026-33828
CVE-2026-33828 is a trust boundary violation vulnerability in Windows Attestation. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and a severity of HIGH.
These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-33828 is a trust boundary violation vulnerability in Windows Attestation. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and a severity of HIGH.
CVE-2026-33113 is a MEDIUM-severity vulnerability in Microsoft Office SharePoint, with a CVSS score of 5.4. The vulnerability allows an authorized attacker to perform spoofing over a network due to improper neutralization of input during web page generation, also known as cross-site scripting (XSS).
CVE-2026-48579 is a critical vulnerability in Microsoft Exchange Online that allows an unauthorized attacker to disclose information over a network. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. It was published on 2026-06-04T23:17:32.830Z and modified on 2026-06-05T16:51:00.523Z.
CVE-2026-48567 is a critical vulnerability in Azure HorizonDB that allows an unauthorized attacker to elevate privileges over a network. The vulnerability has a CVSS score of 10 and a severity of CRITICAL. It was published on 2026-06-04T23:17:32.677Z and modified on 2026-06-05T16:30:23.133Z.
CVE-2026-47655 is a MEDIUM-severity vulnerability (CVSS Score: 6.5) that involves the exposure of sensitive information to an unauthorized actor in Microsoft Graph. An authorized attacker can exploit this vulnerability to disclose information over a network. The vulnerability was published on 2026-06-04T23:17:32.530Z and last modified on 2026-06-05T14:59:51.620Z.
CVE-2026-47644 is a vulnerability in Copilot Chat (Microsoft Edge) that allows an unauthorized attacker to disclose information over a network. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. It was published on [cvePublishedAt] and modified on [cveModifiedAt]. The vulnerability is caused by improper neutralization of special elements in output used by a downstream component ('injection').
CVE-2026-45497 is a HIGH severity vulnerability in Microsoft Copilot, allowing an authorized attacker to execute code over a network due to improper neutralization of special elements used in a command. The vulnerability was published on 2026-06-04T23:17:32.250Z and modified on 2026-06-08T13:55:28.053Z. The CVSS score is 7.7.
CVE-2026-42824 is a medium-severity vulnerability in Microsoft Copilot, a product within the Microsoft 365 suite. The vulnerability, which has a CVSS score of 6.5, is caused by improper neutralization of special elements used in a command, also known as command injection. This allows an unauthorized attacker to disclose information over a network. The vulnerability was first published on [cve-org](https:/ [truncated]
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. In versions up to and including 3.0.1-4-ge2626659, the framework's WebSocket server accepts client-supplied session_id values in task messages and reuses existing in-memory session objects when a matching session_id is found. If a prior session has completed and remains in memory with populated results, a di [truncated]
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. In version 3.0.1-4-ge2626659, the constellation client tracks pending task responses by session_id only and does not verify that a TASK_END message originated from the device that originally received the task. When the constellation sends a task to a target device, it records a pending Future under a session [truncated]
A shared-instance design flaw in Microsoft UFO's WebSocket handler (versions through 3.0.1-4-ge2626659) causes authenticated session response leakage. The UFOWebSocketHandler class is instantiated once and reused across multiple WebSocket connections, storing per-connection protocol objects in mutable instance fields. Each new connection overwrites these fields, causing message handlers to dispatch respon [truncated]
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. In version 3.0.1-4-ge2626659, the WebSocket control plane contains an authenticated role/identity spoofing vulnerability that enables peer task hijacking. The server trusts client-supplied identity and role fields in TASK messages rather than enforcing the role registered for that WebSocket connection. An au [truncated]
CVE-2026-46402 is a path traversal vulnerability in Microsoft UFO, an open-source framework for intelligent automation across devices and platforms. In version 3.0.1-4-ge2626659, the framework uses user-controlled `task_name` values directly when constructing session log paths. An authenticated attacker can supply path traversal sequences (e.g., `../`) in the `task_name` parameter, causing UFO to create l [truncated]
CVE-2026-45322 is a high-severity OS command injection vulnerability in the Microsoft UFO open-source framework for intelligent automation. The vulnerability exists in tagged releases up to and including v3.0.0, specifically within the shell action replay path. The root cause is improper neutralization of special elements used in OS commands (CWE-78), where ShellReceiver.run_shell() passes a command strin [truncated]
A critical authentication bypass vulnerability in Azure Resource Manager (ARM) enables unauthenticated network-based privilege escalation. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates network attack vector, low complexity, no privileges required, no user interaction, and changed scope with high impact across confidentiality, integrity, and availability. The vulnerability is classifi [truncated]
A critical origin validation vulnerability in Microsoft Entra ID permits unauthenticated network-based attackers to escalate privileges. The flaw, rooted in CWE-346 (Origin Validation Error), carries a CVSS 3.1 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating maximum severity with network exploitability, no privileges required, and high impact across confidentiality, integrity, and availabi [truncated]
A command injection vulnerability in M365 Copilot allows network-based information disclosure by unauthenticated attackers. The flaw stems from improper neutralization of special elements in commands (CWE-77). With a CVSS 3.1 score of 6.5 (Medium), this vulnerability requires user interaction but no privileges, enabling remote attackers to extract sensitive information. Microsoft has acknowledged this iss [truncated]
A critical deserialization vulnerability in Microsoft Planetary Computer Pro enables unauthenticated remote attackers to disclose sensitive information over a network. The flaw stems from improper handling of untrusted data during deserialization (CWE-502), with a CVSS 3.1 score of 10.0 indicating maximum severity due to network attack vector, low complexity, no privileges required, and no user interactio [truncated]
A critical command injection vulnerability in Microsoft Copilot enables network-based tampering by unauthenticated attackers. The flaw stems from improper neutralization of special elements in commands (CWE-77), allowing malicious input to execute unintended system commands. With a CVSS 3.1 score of 9.3, this vulnerability presents severe risk due to its network attack vector, low complexity, and high imp [truncated]
A critical unauthenticated remote code execution vulnerability exists in Azure Orbital Spatio due to unrestricted file upload of dangerous types (CWE-434). The vulnerability carries a CVSS 3.1 score of 10.0 (Critical), indicating maximum severity with network attack vector, low attack complexity, no privileges required, no user interaction, and scope change affecting confidentiality, integrity, and availa [truncated]
A critical vulnerability in Azure Virtual Network Gateway permits network-based code execution by authenticated attackers. The flaw stems from improper input validation (CWE-20). Microsoft has acknowledged this issue via their Security Response Center. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates network attack vector, low complexity, low privileges required, no user interaction, an [truncated]
A high-severity authorization bypass vulnerability in Azure Privileged Identity Management (PIM) permits an authenticated attacker to escalate privileges via network access. The flaw stems from improper handling of user-controlled keys (CWE-639), allowing privilege elevation without additional user interaction. Published by NVD on 2026-05-22 and last modified on 2026-05-26, this vulnerability is currently [truncated]
A critical authentication bypass vulnerability in Microsoft Azure Active Directory B2C enables network-based privilege escalation without requiring prior authentication. The flaw, rated CVSS 9.1, stems from an alternate path or channel that circumvents intended authentication controls (CWE-288). Published by NVD on May 22, 2026, with subsequent modification on May 26, 2026, the entry remains under active [truncated]
CVE-2026-26147 is a HIGH severity vulnerability (CVSS 7.7) in Azure Compute Gallery resulting from improper input validation (CWE-20). An authorized attacker can exploit this flaw to disclose information over a network. The vulnerability was published on 2026-05-22 and last modified on 2026-05-26. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) indicates network attack vector, low attack co [truncated]
A privilege escalation vulnerability in Azure Entra ID (formerly Azure Active Directory) allows network-based attackers to elevate privileges without authentication. The vulnerability, published 2026-05-22 and last modified 2026-05-26, carries a CVSS 3.1 score of 7.5 (HIGH) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N—indicating network attack vector, low complexity, no privileges required, no use [truncated]
A critical command injection vulnerability in Microsoft Power Pages enables unauthenticated remote code execution over the network. The vulnerability, published 2026-05-22 and last modified 2026-05-26, carries a CVSS 3.1 score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Microsoft has assigned CWE-77 (Improper Neutralization of Special Elements used in a Command). The NVD entry rema [truncated]
CVE-2026-45584 is a high-severity heap-based buffer overflow in Microsoft’s Malware Protection Engine, associated with Microsoft Defender, that can allow an unauthorized attacker to execute code over the network. NVD lists the issue as AV:N/AC:H/PR:N/UI:N with CWE-122 and a CVSS 3.1 score of 8.1. Microsoft’s advisory is the official vendor reference for remediation guidance.
CVE-2026-42834 is a high-severity local privilege escalation issue in Azure Portal Windows Admin Center. Microsoft and NVD describe it as improper link resolution before file access (CWE-59), which can allow an authorized attacker with local access and limited privileges to elevate privileges on the host. NVD published the CVE on 2026-05-20 and updated it the same day; the vulnerability is scored 7.8 HIGH.
On 2026-05-20, Microsoft published CVE-2026-45585 for a Windows security feature bypass publicly referred to as “YellowKey.” Microsoft says a proof of concept was made public, and the CVE was issued to provide mitigation guidance until a security update is available. NVD lists affected Windows 11 x64 releases 24H2, 25H2, and 26H1, plus Windows Server 2025.
Microsoft Defender Denial of Service Vulnerability. A denial of service vulnerability exists in Microsoft Defender, which could allow an attacker to cause a denial of service condition. Defenders should assess exposure and apply mitigations according to vendor instructions. This vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog, indicating that it is known to be exploited in the [truncated]