VULNERABILITY INTELLIGENCE TOPIC
Microsoft Vulnerabilities
Recent Microsoft CVEs affecting Windows, Office, Exchange, Active Directory, Azure and related products.
How to use this page
Validate affected versions against Microsoft advisories and prioritize internet-facing systems, authentication services and KEV-listed issues.
Latest matching records
CVE-2026-96765The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to inCVE-2026-104759The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_TokCVE-2026-62367Vikunja is an open-source self-hosted task management platform. In versions 1.0.0 through 2.3.0, when an administrator enables the per-provider `emailfallback` option on an OpenID Connect provider, Vikunja links an SSO lCVE-2026-96207Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.CVE-2026-94510Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.CVE-2026-88131Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.CVE-2026-84058IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a nCVE-2026-107782System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. AttackerCVE-2026-107225Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check only upper bounds for attacker-controlled style-CVE-2026-107224Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed siz