Autor: Peter Leibling

CVE-2026-23661 Azure IoT Explorer Information Disclosure Vulnerability

Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-23667 Broadcast DVR Elevation of Privilege Vulnerability

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

CVE-2026-26105 Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of input during web page generation (‚cross-site scripting‘) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-24282 Push message Routing Service Elevation of Privilege Vulnerability

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

CVE-2026-25188 Windows Telephony Service Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.

CVE-2026-26114 Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-26106 Microsoft SharePoint Server Remote Code Execution Vulnerability

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.