Total
14 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-83941 | 1 Microsoft | 1 Entra Id | 2026-09-16 | N/A | 9.9 CRITICAL |
| Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-62916 | 1 Microsoft | 1 Entra Id | 2026-09-08 | N/A | 9.1 CRITICAL |
| Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69851 | 1 Microsoft | 1 Entra Id | 2026-08-25 | N/A | 9.9 CRITICAL |
| Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69836 | 1 Microsoft | 1 Entra Id | 2026-08-25 | N/A | 10.0 CRITICAL |
| Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-62869 | 1 Microsoft | 1 Entra Id | 2026-08-13 | N/A | 8.8 HIGH |
| Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-42901 | 1 Microsoft | 1 Entra Id | 2026-07-23 | N/A | 10.0 CRITICAL |
| Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-33843 | 1 Microsoft | 1 Entra Id | 2026-07-23 | N/A | 9.1 CRITICAL |
| Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-40379 | 1 Microsoft | 1 Entra Id | 2026-06-17 | N/A | 9.3 CRITICAL |
| Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-35431 | 1 Microsoft | 1 Entra Id | 2026-06-17 | N/A | 10.0 CRITICAL |
| Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-24305 | 1 Microsoft | 1 Entra Id | 2026-06-17 | N/A | 9.3 CRITICAL |
| Azure Entra ID Elevation of Privilege Vulnerability | |||||
| CVE-2025-59246 | 1 Microsoft | 1 Entra Id | 2026-06-17 | N/A | 9.8 CRITICAL |
| Azure Entra ID Elevation of Privilege Vulnerability | |||||
| CVE-2025-59218 | 1 Microsoft | 1 Entra Id | 2026-06-17 | N/A | 9.6 CRITICAL |
| Azure Entra ID Elevation of Privilege Vulnerability | |||||
| CVE-2025-55241 | 1 Microsoft | 1 Entra Id | 2026-06-17 | N/A | 10.0 CRITICAL |
| Azure Entra ID Elevation of Privilege Vulnerability | |||||
| CVE-2024-43477 | 1 Microsoft | 1 Entra Id | 2026-06-17 | N/A | 7.5 HIGH |
| Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant. | |||||
