A vulnerability classified as critical was found in Microsoft Azure AI Search. Affected by this vulnerability is an unknown functionality. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-56167. The attack may be launched remotely. There is no exploit available.
This product is a managed service, so users are unable to manage vulnerability countermeasures on their own.
A vulnerability classified as critical has been found in Microsoft Azure Key Vault. Affected is an unknown function. This manipulation causes improper authentication.
This vulnerability appears as CVE-2026-62825. The attack may be initiated remotely. There is no available exploit.
This product is a managed service. This means that users cannot maintain vulnerability countermeasures themselves.
A vulnerability described as critical has been identified in Microsoft Azure DNS. This impacts an unknown function. The manipulation results in improper authorization.
This vulnerability is reported as CVE-2026-58275. The attack can be launched remotely. No exploit exists.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
A vulnerability marked as critical has been reported in Microsoft Copilot. This affects an unknown function. The manipulation leads to deserialization.
This vulnerability is documented as CVE-2026-50517. The attack can be initiated remotely. There is not any exploit available.
This product is available as a managed service. Users are not able to maintain vulnerability countermeasures themselves.
A vulnerability labeled as critical has been found in Microsoft Azure API Management. The impacted element is an unknown function. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-35425. It is possible to launch the attack remotely. No exploit is available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.
A vulnerability identified as very critical has been detected in Microsoft Azure Red Hat OpenShift. The affected element is an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-56160. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service, therefore users are not responsible for maintaining vulnerability countermeasures.
A vulnerability categorized as critical has been discovered in Microsoft Account. Impacted is an unknown function. Such manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2026-56165. The attack may be performed from remote. There is no available exploit.
This product is a managed service, which means users themselves cannot handle vulnerability countermeasures.
A vulnerability was found in Microsoft Surface Management Services. It has been rated as very critical. This issue affects some unknown processing. This manipulation causes improper input validation.
This vulnerability is tracked as CVE-2026-54120. The attack is possible to be carried out remotely. No exploit exists.
This product is a managed service, so users do not have direct control over vulnerability countermeasures.
A vulnerability was found in Microsoft Graph. It has been declared as problematic. This vulnerability affects unknown code. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-49159. The attack can be executed remotely. There is not any exploit available.
This product is a managed service, indicating that users are not permitted to maintain vulnerability countermeasures themselves.
A vulnerability was found in Microsoft Exchange Server. It has been classified as very critical. This affects an unknown part. The manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-56191. Remote exploitation of the attack is possible. No exploit is available.
This product is provided as a managed service, meaning users do not have the ability to maintain vulnerability countermeasures themselves.