CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47647 Microsoft US
Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-47647 Microsoft US
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
EPSS 0.00 CVE-2026-42895 Microsoft US
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-47633 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-32208 Microsoft US
Huntress Managed ISPM finds and closes Microsoft 365 identity gaps before attackers do. Learn why visibility isn't enough and what real identity hardening takes.
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
EPSS 0.11 CVE-2026-50656 Microsoft US
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
Microsoft SK
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft és az Adobe szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 206 különböző biztonsági hibát javított, köztük 3 db nulladik napi (zero-day) sebezhetőséget is, […]
Huntress traced device code phishing from Tencent Cloud to Kali365, a Microsoft 365 kit that steals tokens and keeps access even after MFA or password resets.
209 patches + 388 advisories = welcome to summer 2026Categories: Threat ResearchTags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY
Microsoft GB
On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.
Microsoft JP
I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for June 2026For June,…
KEV ✓ EPSS 0.54 CVSS 10.0 CVE-2025-10263 CVE-2026-32193 CVE-2026-41091 CVE-2026-44815 CVE-2026-45585 CVE-2026-45586 CVE-2026-45657 CVE-2026-47291 CVE-2026-47644 CVE-2026-48567 CVE-2026-49160 CVE-2026-50507 Adobe Microsoft US
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-44810 Microsoft US
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
EPSS 0.02 CVE-2026-42986 Microsoft US
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50512 Microsoft US
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-50511 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-48562 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-48560 Microsoft US
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
EPSS 0.35 CVE-2026-45484 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45481 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47640 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47634 Microsoft US
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-47293 Microsoft US
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45647 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-45644 Microsoft US
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-45476 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45465 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45464 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45462 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.02 CVE-2026-45454 Microsoft veřejná správa finance zdravotnictví školství US
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-42835 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-33113 Microsoft US
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-49161 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47641 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47639 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47638 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-47637 Microsoft US
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
EPSS 0.00 CVE-2026-47635 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-47631 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
EPSS 0.00 CVE-2026-32193 Microsoft US
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-41092 Microsoft US
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45650 Microsoft US
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
EPSS 0.00 CVE-2026-45642 Microsoft US
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
EPSS 0.00 CVE-2026-45606 Microsoft US
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-45583 Microsoft US
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-45503 Microsoft US
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
EPSS 0.20 CVE-2026-45502 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-45501 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-45500 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45453 Microsoft US
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-42902 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45483 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45479 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45468 Microsoft US
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
EPSS 0.01 CVE-2026-45467 Microsoft US
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-41108 Microsoft US
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-47298 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
EPSS 0.00 CVE-2026-45482 Microsoft GitHub US
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-40371 Microsoft US