CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Plaintext Storage of a Password vulnerability (CVE-2026-15933) has been found in OptimiDoc Server (On-Premise) software.
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.9, CVEs: CVE-2026-20354, CVE-2026-20355, Summary: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these…
CVSS 5.9 CVE-2026-20354 CVE-2026-20355 Cisco FI US 2 zdrojů
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
KEV ✓ EPSS 0.00 CVE-2026-82329 JFrog US CA 3 zdrojů
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
KEV ✓ EPSS 0.71 CVE-2026-42897 CVE-2026-62911 Microsoft US
Aggiornamenti di sicurezza sanano sanano una vulnerabilità con gravità “alta” nel linguaggio di programmazione Go. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati di aggirare i meccanismi di autenticazione sui sistemi interessati.
EPSS 0.00 CVE-2026-56854 Go IT
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.