Security Risk Category

Microsoft Security Risks — Page 5

Published vulnerability pages connected to Microsoft. Each page keeps one canonical URL and focused remediation guidance.

212 published Microsoft risks

Microsoft risks

Showing 145–180 of 212 published risks.

highEPSS 0.008

CVE-2026-50521 in Microsoft Edge Chromium

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

CVE-2026-50521browsermicrosoftremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.004

CVE-2026-26145 Azure Synapse Vulnerability

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

CVE-2026-26145microsoftcloud-securityauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.005

CVE-2026-41106 Microsoft 365 Copilot Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-41106microsoftcloud-securityopen-redirect

Updated Jul 14, 2026

criticalEPSS 0.006

CVE-2026-45499 Azure OpenAI Vulnerability

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

CVE-2026-45499microsoftcloud-securityssrf

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-54998 Microsoft Exchange Online Vulnerability

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

CVE-2026-54998microsoftauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.006

CVE-2026-57100 Microsoft Entra Provisioning Service Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

CVE-2026-57100microsoftcloud-securityssrf

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-45488 edge chromium vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-45488browsermicrosoft

Updated Jul 14, 2026

mediumEPSS 0.005

CVE-2026-45489 edge chromium vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2026-45489browsermicrosoftauthentication-bypass

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-55945 edge chromium vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

CVE-2026-55945browsermicrosoftrace-condition

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-56645 edge chromium vulnerability

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-56645browsermicrosoftmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.007

CVE-2026-56646 edge chromium vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-56646browsermicrosoftinformation-disclosure

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57974 edge chromium vulnerability

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57974browsermicrosoftinput-validation

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57975 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57975browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57977 edge chromium vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57977browsermicrosoftxss

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57981 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57981browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-57983 edge chromium vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-57983browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57984 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57984browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-57985 edge chromium vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57985browsermicrosoftinput-validation

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57986 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57986browsermicrosoftmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.006

CVE-2026-57987 edge chromium vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57987browsermicrosoftssrf

Updated Jul 14, 2026

highEPSS 0.005

CVE-2026-57988 edge chromium vulnerability

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57988browsermicrosoftpath-traversal

Updated Jul 14, 2026

highEPSS 0.007

CVE-2026-57991 edge chromium vulnerability

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-57991browsermicrosoftpath-traversal

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-57992 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-57992browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.006

CVE-2026-57993 edge chromium vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-57993browsermicrosoftssrf

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58276 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58276browsermicrosoftmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.003

CVE-2026-58278 edge chromium vulnerability

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58278browsermicrosoftssrf

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58282 edge chromium vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58282browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58283 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58283browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58284 edge chromium vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58284browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58285 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58285browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58286 edge chromium vulnerability

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-58286browsermicrosoftauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58287 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58287browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-58288 edge chromium vulnerability

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58288browsermicrosoftmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.004

CVE-2026-58289 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58289browsermicrosoftmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-58290 edge chromium vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2026-58290browsermicrosoftmemory-corruption

Updated Jul 13, 2026

mediumEPSS 0.006

CVE-2026-58291 edge chromium vulnerability

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-58291browsermicrosoft

Updated Jul 13, 2026