Kategorie: Allgemein

Chrome: Update stopft drei kritische Sicherheitslücken

Das in der Nacht zum Donnerstag veröffentlichte Chrome-Update schließt 26 Sicherheitslücken, darunter drei kritische.

CVE-2026-26139 Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-23658 Azure DevOps: msazure Elevation of Privilege Vulnerability

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-23659 Azure Data Factory Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

CVE-2026-26138 Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-32191 Microsoft Bing Images Remote Code Execution Vulnerability

Improper neutralization of special elements used in an os command (‚os command injection‘) in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

CVE-2026-32194 Microsoft Bing Images Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command (‚command injection‘) in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

CVE-2026-26136 Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command (‚command injection‘) in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-32169 Azure Cloud Shell Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.