Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-09-18
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.009
Published
2026-09-18
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.007
Published
2026-09-17
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.007
Published
2026-09-17
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.01
Published
2026-09-17
CVE-2026-87886
Known exploited
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-09-17
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-09-17
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.0
EPSS Score
0.004
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.006
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.005
Published
2026-09-17


Contact Us

Shodan ® - All rights reserved