Security Risk Category
Microsoft Security Risks — Page 5
Published vulnerability pages connected to Microsoft. Each page keeps one canonical URL and focused remediation guidance.
212 published Microsoft risks
Microsoft risks
Showing 145–180 of 212 published risks.
CVE-2026-50521 in Microsoft Edge Chromium
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-26145 Azure Synapse Vulnerability
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Updated Jul 14, 2026
CVE-2026-41106 Microsoft 365 Copilot Vulnerability
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Updated Jul 14, 2026
CVE-2026-45499 Azure OpenAI Vulnerability
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Updated Jul 14, 2026
CVE-2026-54998 Microsoft Exchange Online Vulnerability
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Updated Jul 14, 2026
CVE-2026-57100 Microsoft Entra Provisioning Service Vulnerability
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Updated Jul 14, 2026
CVE-2026-45488 edge chromium vulnerability
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-45489 edge chromium vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Updated Jul 14, 2026
CVE-2026-55945 edge chromium vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.
Updated Jul 14, 2026
CVE-2026-56645 edge chromium vulnerability
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-56646 edge chromium vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-57974 edge chromium vulnerability
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57975 edge chromium vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57977 edge chromium vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-57981 edge chromium vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57983 edge chromium vulnerability
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
Updated Jul 14, 2026
CVE-2026-57984 edge chromium vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57985 edge chromium vulnerability
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57986 edge chromium vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57987 edge chromium vulnerability
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-57988 edge chromium vulnerability
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57991 edge chromium vulnerability
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Updated Jul 14, 2026
CVE-2026-57992 edge chromium vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-57993 edge chromium vulnerability
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-58276 edge chromium vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-58278 edge chromium vulnerability
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-58282 edge chromium vulnerability
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-58283 edge chromium vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-58284 edge chromium vulnerability
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-58285 edge chromium vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-58286 edge chromium vulnerability
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Updated Jul 14, 2026
CVE-2026-58287 edge chromium vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-58288 edge chromium vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-58289 edge chromium vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 14, 2026
CVE-2026-58290 edge chromium vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Updated Jul 13, 2026
CVE-2026-58291 edge chromium vulnerability
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Updated Jul 13, 2026
